performance-engineer

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a pure-prompt persona designed to interpret performance metrics from a specific local directory (.unity-review/). No malicious patterns, obfuscation, or data exfiltration attempts were detected.
  • [DATA_EXFILTRATION]: File access is restricted to localized report data within the project directory. The skill does not access sensitive user credentials, SSH keys, or environment variables, and it contains no instructions for outbound network communication.
  • [EXTERNAL_DOWNLOADS]: Installation instructions reference the author's own repository and official tooling. No suspicious third-party downloads or remote script executions (e.g., pipe-to-shell) are present.
  • [PROMPT_INJECTION]: The skill processes local report files which could theoretically contain instructions. However, the risk is mitigated because the skill has no tool access (no allowed-tools) and its behavior is strictly constrained to generating a performance report, preventing any harmful downstream actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 01:15 PM
Security Audit — agent-trust-hub — performance-engineer