polygraph.so
A

packages/plugins/uniswap-cca/skills/configurator

github/Uniswap/uniswap-ai#packages/plugins/uniswap-cca/skills/configurator

litmus-skill-v3 · 2026-07-05

graded at commit 07ff0f0 · 2026-02-17

The packages/plugins/uniswap-cca/skills/configurator skill is graded A by polygraph under litmus-skill-v3, as of 2026-07-05, anchored to its content hash.

Graded under litmus-skill-v3; the current skill methodology is litmus-skill-v2. A re-run may change the grade.

Self-reported Configure CCA (Continuous Clearing Auction) smart contract parameters through an interactive bulk form flow. Use when user says "configure auction", "cca auction", "setup token auction", "auction configuration", "continuous auction", or mentions CCA contracts.” — the skill’s own SKILL.md description at the graded commit, not part of the grade.

A static safety grade — a deterministic scan of the skill’s SKILL.md and bundled files. An A means static-clean, not behavioral proof: a skill’s instructions are interpreted by an agent at runtime.

S-01 Prompt-injection / context-poisoningpass
S-03 Data-exfiltration instructionspass
S-04 Dangerous bundled commandspass

no dangerous commands in the body; no bundled scripts

content hash · 0xfc43e68da4…e9f7

Source · github.com/Uniswap/uniswap-ai/tree/main/packages/plugins/uniswap-cca/skills/configurator

Watch for changes

This grade is a snapshot of the skill’s files at one commit. Get an email when a new commit changes packages/plugins/uniswap-cca/skills/configurator and polygraph re-runs the litmus — one message per change, one-click unsubscribe.

Monitor this skill

Reproduce this grade

The skill litmus is open and deterministic. Point it at the skill directory and compare the grade and content hash — a false grade is falsifiable, not merely disputable.

npx -p @polygraphso/litmus polygraphso-litmus-skill <skill-dir>

Embed this badge

Drop it in the skill’s README, docs, or listing. It always shows the current grade and links back here.

polygraph skill grade A
Markdown — badge
[![polygraph](https://www.polygraph.so/api/badge/skill?skill=github/Uniswap/uniswap-ai/packages/plugins/uniswap-cca/skills/configurator)](https://www.polygraph.so/skill/github/Uniswap/uniswap-ai/packages/plugins/uniswap-cca/skills/configurator)
HTML — badge
<a href="https://www.polygraph.so/skill/github/Uniswap/uniswap-ai/packages/plugins/uniswap-cca/skills/configurator"><img src="https://www.polygraph.so/api/badge/skill?skill=github/Uniswap/uniswap-ai/packages/plugins/uniswap-cca/skills/configurator" alt="polygraph grade"></a>
Markdown — card
[![polygraph](https://www.polygraph.so/api/badge/skill/card?skill=github/Uniswap/uniswap-ai/packages/plugins/uniswap-cca/skills/configurator)](https://www.polygraph.so/skill/github/Uniswap/uniswap-ai/packages/plugins/uniswap-cca/skills/configurator)

Questions

What does the A skill grade mean for packages/plugins/uniswap-cca/skills/configurator?
It’s a static safety grade(A/B/D/F) from a deterministic scan of the skill’s SKILL.md and bundled files. An A means static-clean — not behavioral proof, since a skill’s instructions are interpreted by an agent at runtime.
What did polygraph check?
Three static checks: S-01 prompt-injection and context-poisoning, S-03 data-exfiltration instructions, and S-04 dangerous bundled commands. The full battery is in the methodology.
How do I reproduce this grade?
Run npx -p @polygraphso/litmus polygraphso-litmus-skill <skill-dir>. The scan is open and deterministic, anchored to the skill’s content hash, so the same directory yields the same grade.