flame-audit
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill suggests fetching and executing the
lighthousetool and thechrome-devtools-mcppackage usingnpx. While these are standard performance auditing tools, they involve downloading code from the npm registry. - [COMMAND_EXECUTION]: The skill executes shell-based commands including
npx lighthousefor page auditing andgrepfor identifying hot-paths in the codebase. These actions are performed based on external parameters like URLs and function names. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could potentially contain malicious instructions.
- Ingestion points:
SKILL.md(Phases 1-3) defines workflows to ingest data from external URLs, network request logs, and performance trace files (such as.cpuprofileand.json). - Boundary markers: Absent; the instructions do not include specific delimiters or guardrails to prevent the agent from following instructions that might be embedded in the audited web content or trace metadata.
- Capability inventory:
SKILL.md(Phases 0, 1, and 5) grants the agent capabilities to navigate to arbitrary URLs, capture traces, execute shell commands vianpx, and search local workspace files usinggrep. - Sanitization: Absent; the skill does not describe any validation or sanitization of data retrieved from external sources before it is analyzed and used to suggest code modifications.
Audit Metadata