performance-review
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes source code files which are externally provided and untrusted. Maliciously crafted code could attempt to influence the agent's summary or recommendations through specific AST patterns or comments that match the skill's detectors.
- Ingestion points: Source code files read from the local file system (SKILL.md).
- Boundary markers: None identified in the provided modules for the analyzed source content.
- Capability inventory: File system read access, shell command execution (via documentation for verification and visualization), and generation of structured review findings.
- Sanitization: No explicit sanitization of AST-extracted text (e.g., variable names or anchors) is mentioned before inclusion in reports.
- [EXTERNAL_DOWNLOADS]: The
modules/kuva-visualization.mdfile provides instructions to download and installkuva, a Rust scientific plotting library, usingcargo install kuvafrom the official Crates.io package registry. This is documented for the purpose of visualizing benchmark results. - [COMMAND_EXECUTION]: The skill's verification workflow includes executing a local script
plugins/imbue/scripts/citation_verifier.pyto validate that detected hotspots exist in the source code. It also includes documentation for executingkuva,pytest, andgitcommands as part of the performance analysis process.
Audit Metadata