flame-audit

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill suggests fetching and executing the lighthouse tool and the chrome-devtools-mcp package using npx. While these are standard performance auditing tools, they involve downloading code from the npm registry.
  • [COMMAND_EXECUTION]: The skill executes shell-based commands including npx lighthouse for page auditing and grep for identifying hot-paths in the codebase. These actions are performed based on external parameters like URLs and function names.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could potentially contain malicious instructions.
  • Ingestion points: SKILL.md (Phases 1-3) defines workflows to ingest data from external URLs, network request logs, and performance trace files (such as .cpuprofile and .json).
  • Boundary markers: Absent; the instructions do not include specific delimiters or guardrails to prevent the agent from following instructions that might be embedded in the audited web content or trace metadata.
  • Capability inventory: SKILL.md (Phases 0, 1, and 5) grants the agent capabilities to navigate to arbitrary URLs, capture traces, execute shell commands via npx, and search local workspace files using grep.
  • Sanitization: Absent; the skill does not describe any validation or sanitization of data retrieved from external sources before it is analyzed and used to suggest code modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — flame-audit