cwv-audit

Pass

Audited by Gen Agent Trust Hub on May 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a comprehensive technical guide for Core Web Vitals optimization and monitoring. No malicious patterns or security risks were identified.
  • [EXTERNAL_DOWNLOADS]: The documentation provides instructions for installing the official web-vitals library from npm. This is a well-known library maintained by Google and is appropriate for the skill's purpose.
  • [COMMAND_EXECUTION]: The skill permits the use of the Bash tool, which is standard for performance auditing tasks. No suspicious or high-risk command execution patterns were found.
  • [DATA_EXFILTRATION]: The tool access for Google Search Console and Google Analytics 4 (via Cogny MCP) is consistent with the skill's intended functionality of retrieving performance data for analysis. There is no evidence of unauthorized data transfer or hardcoded credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
May 2, 2026, 06:43 AM
Security Audit — agent-trust-hub — cwv-audit