benchmark

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were identified.
  • [PROMPT_INJECTION]: The skill includes functionality to access external URLs and API endpoints for performance measurement. While this presents a surface for indirect prompt injection, it is the primary intended function of the tool. Evidence Chain: 1. Ingestion points: Target URLs and API responses (SKILL.md); 2. Boundary markers: Absent; 3. Capability inventory: Browser navigation, API requests, and local build execution (SKILL.md); 4. Sanitization: Not specified.
  • [COMMAND_EXECUTION]: The skill documents procedures for measuring local build performance, including Docker builds and test suite execution. These are standard development activities and do not involve unauthorized privilege escalation or suspicious command patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 11:08 AM
Security Audit — agent-trust-hub — benchmark