flame-audit

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill utilizes npx to run the Lighthouse CLI for performance audits. This involves downloading and executing code from the npm registry at runtime, specifically targeting the Lighthouse tool which is a well-known service provided by Google.
  • [EXTERNAL_DOWNLOADS]: Fetches auditing tools and suggests the configuration of MCP servers from the npm registry to support its profiling and navigation capabilities.
  • [COMMAND_EXECUTION]: Employs shell-based execution (npx lighthouse) to perform fallback audits, which incorporates a user-provided URL into the command string.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and interpret external data from web pages and performance artifacts, creating a standard surface for indirect prompt injection.
  • Ingestion points: Target URLs visited via browser navigation and user-supplied trace artifacts (SKILL.md).
  • Boundary markers: No explicit delimiters or instructions to ignore embedded instructions are specified for the processing of audited page content.
  • Capability inventory: The skill possesses capabilities for browser navigation, network request inspection, and shell command execution.
  • Sanitization: No specific sanitization or filtering logic is mentioned for data retrieved from external websites during the audit process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:22 PM
Security Audit — agent-trust-hub — flame-audit