spring-boot-performance-and-resilience

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No prompt injection patterns, bypass markers, or role-play instructions were detected. The instructions are focused on technical Spring Boot configuration.
  • [DATA_EXFILTRATION]: No exfiltration patterns found. The skill does not access sensitive local file paths (like ~/.ssh or .env) or attempt to send data to external unknown domains.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials, API keys, or tokens were found in the skill content.
  • [REMOTE_CODE_EXECUTION]: The skill does not perform remote script execution (e.g., curl|bash). It recommends standard, well-known libraries like Resilience4j, Bucket4j, and HikariCP.
  • [COMMAND_EXECUTION]: No dangerous shell command execution was found. Subprocess usage is limited to standard performance testing tools like Gatling, k6, or JMeter.
  • [EXTERNAL_DOWNLOADS]: The skill does not download external code. References to external tools and libraries are for standard industry software used in Spring Boot development.
  • [DYNAMIC_EXECUTION]: While the skill generates configuration files and load-test scripts, it does so using predefined technical templates and does not incorporate untrusted external input into executable logic.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific data (SLOs, architecture documents) but includes specific operating rules to prevent safety violations, such as adhering to organizational security and observability standards.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 08:35 AM
Security Audit — agent-trust-hub — spring-boot-performance-and-resilience