performance-profiling
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a Python script
scripts/lighthouse_audit.pythat executes thelighthousecommand-line tool usingsubprocess.run. The command is constructed as a list of arguments, which is a secure practice to prevent shell injection, though it lacks explicit validation of the URL parameter beyond passing it as a positional argument. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data by reading JSON reports generated by the Lighthouse CLI. While this represents an attack surface for indirect prompt injection (where malicious content in a web page might theoretically influence the audit report content), the script only extracts specific numeric scores and generates a summary based on predefined logic, significantly limiting any potential impact.
- Ingestion points: Reads temporary JSON files generated by the
lighthouseCLI inscripts/lighthouse_audit.py. - Boundary markers: None explicitly present in the data ingestion phase.
- Capability inventory: Uses
subprocess.runto call the auditor andos.unlinkfor temporary file cleanup. - Sanitization: The script performs type conversion (casting scores to integers) and uses a hardcoded conditional structure for summary generation, which mitigates simple text-based injection.
Audit Metadata