skills/celeroncoder/skills/web-perf/Gen Agent Trust Hub

web-perf

Warn

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to add an MCP configuration that uses npx -y chrome-devtools-mcp@latest. This directs the system to download the chrome-devtools-mcp package from the npm registry at runtime.\n- [REMOTE_CODE_EXECUTION]: The instruction to use npx -y chrome-devtools-mcp@latest facilitates the execution of remote code in the user's local environment to enable the skill's auditing features.\n- [DATA_EXFILTRATION]: Through the use of tools like list_network_requests and get_network_request, the skill accesses full network transaction details. This can expose sensitive data such as session cookies, Authorization headers, and API keys to the agent's context during an audit.\n- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection attacks because it ingests and analyzes content from third-party websites that could influence the agent's behavior.\n
  • Ingestion points: Web content and DOM snapshots are retrieved using navigate_page and take_snapshot (SKILL.md).\n
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the retrieved web content as untrusted or to ignore instructions contained within it.\n
  • Capability inventory: The skill possesses capabilities to navigate the browser, start performance traces, and inspect specific network requests through the chrome-devtools server.\n
  • Sanitization: No sanitization or filtering logic is specified for the data gathered from the target websites.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — web-perf