skills/chikage0o0/opencode/web-perf/Gen Agent Trust Hub

web-perf

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external websites and local codebases, which creates a surface for indirect prompt injection where malicious content in a website or file could influence the agent's behavior.
  • Ingestion points: The skill ingests untrusted data through navigate_page results, network request details, and local source code files during codebase analysis in SKILL.md.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat external content as untrusted data or to ignore instructions embedded within the audited pages.
  • Capability inventory: The skill utilizes tools for navigating web pages, analyzing network traffic, taking accessibility snapshots, and reading local filesystem content.
  • Sanitization: The instructions do not define any sanitization or validation steps for content retrieved from external URLs before it is processed by the agent.
  • [EXTERNAL_DOWNLOADS]: The skill recommends the installation and execution of an external package from the NPM registry to enable its core functionality.
  • Evidence: The configuration section in SKILL.md suggests adding "command": ["npx", "-y", "chrome-devtools-mcp@latest"] to the user's MCP configuration.
  • Context: While NPM is a well-known service, the recommendation uses an unpinned version (@latest) for a third-party package, which avoids version lock-in and can be a vector for supply chain risks if the upstream package is updated with malicious code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 01:25 AM
Security Audit — agent-trust-hub — web-perf