performance
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill guides the agent to install
@tanstack/react-virtualandrollup-plugin-visualizerusing package managers. These are widely used, reputable packages within the web development community and are appropriate for the skill's stated purpose. - [COMMAND_EXECUTION]: The skill employs shell commands such as
pnpm run build,pnpm run preview, andgrepto analyze performance and locate sub-optimal code patterns. These operations are standard for performance auditing and codebase maintenance. - [INDIRECT_PROMPT_INJECTION]: The skill instructions include the interpolation of
$ARGUMENTSinto its workflow to scope analysis to specific files or directories. While this introduces a surface where malformed user input could theoretically influence agent actions, it is a standard mechanism for providing context to the tool. - Ingestion points: User-provided
$ARGUMENTSare used in the description and instruction steps. - Boundary markers: None explicitly defined in the instruction text.
- Capability inventory: Uses
Shell,Read,Write,Grep, andGlobtools. - Sanitization: None explicitly defined; relies on the agent's underlying execution environment.
Audit Metadata