performance

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill guides the agent to install @tanstack/react-virtual and rollup-plugin-visualizer using package managers. These are widely used, reputable packages within the web development community and are appropriate for the skill's stated purpose.
  • [COMMAND_EXECUTION]: The skill employs shell commands such as pnpm run build, pnpm run preview, and grep to analyze performance and locate sub-optimal code patterns. These operations are standard for performance auditing and codebase maintenance.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions include the interpolation of $ARGUMENTS into its workflow to scope analysis to specific files or directories. While this introduces a surface where malformed user input could theoretically influence agent actions, it is a standard mechanism for providing context to the tool.
  • Ingestion points: User-provided $ARGUMENTS are used in the description and instruction steps.
  • Boundary markers: None explicitly defined in the instruction text.
  • Capability inventory: Uses Shell, Read, Write, Grep, and Glob tools.
  • Sanitization: None explicitly defined; relies on the agent's underlying execution environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:14 PM