flame-audit
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill utilizes
npxto run the Lighthouse CLI for performance audits. This involves downloading and executing code from the npm registry at runtime, specifically targeting the Lighthouse tool which is a well-known service provided by Google. - [EXTERNAL_DOWNLOADS]: Fetches auditing tools and suggests the configuration of MCP servers from the npm registry to support its profiling and navigation capabilities.
- [COMMAND_EXECUTION]: Employs shell-based execution (
npx lighthouse) to perform fallback audits, which incorporates a user-provided URL into the command string. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and interpret external data from web pages and performance artifacts, creating a standard surface for indirect prompt injection.
- Ingestion points: Target URLs visited via browser navigation and user-supplied trace artifacts (SKILL.md).
- Boundary markers: No explicit delimiters or instructions to ignore embedded instructions are specified for the processing of audited page content.
- Capability inventory: The skill possesses capabilities for browser navigation, network request inspection, and shell command execution.
- Sanitization: No specific sanitization or filtering logic is mentioned for data retrieved from external websites during the audit process.
Audit Metadata