audit-speed

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of markdown documentation, diagnostic trees, and output templates. No scripts, binaries, or active configuration files are present in the package.
  • [EXTERNAL_DOWNLOADS]: The documentation references external tools hosted at seojuice.com (CWV Impact Calculator and Critical CSS Generator). These are provided as informational resources for the user to visit manually and do not involve the agent performing automated downloads or remote code execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for the agent to ingest and analyze data from external URLs or tool reports (such as PageSpeed Insights).
  • Ingestion points: Instructions in SKILL.md advise gathering data from user-provided URLs and audit reports.
  • Boundary markers: None present in the provided templates.
  • Capability inventory: No file-system, network, or subprocess tools are included or requested by this specific skill.
  • Sanitization: No sanitization logic is provided.
  • Since the skill does not include or request access to exploitable capabilities (like shell execution or network exfiltration), the attack surface for indirect prompt injection within the context of this skill is negligible.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:44 PM
Security Audit — agent-trust-hub — audit-speed