performance-profiling

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructional content for legitimate performance profiling tasks using standard tools like Node.js inspector, Clinic.js, 0x, and Chrome DevTools. No malicious patterns were detected.
  • [EXTERNAL_DOWNLOADS]: The skill references well-known and widely used developer tools and libraries including clinic, 0x, autocannon, lighthouse, lru-cache, react-window, and @welldone-software/why-did-you-render. These are standard packages within the Node.js and React ecosystems.
  • [COMMAND_EXECUTION]: The skill includes instructions for running profiling commands via the Bash tool. These commands (e.g., node --inspect, clinic doctor, 0x) are standard practices for developers diagnosing performance issues and do not exhibit malicious patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze user-provided profiling data (such as CPU profiles or heap snapshots). While this constitutes an ingestion point for external data, the skill provides a robust framework of classification rules to maintain safe and accurate analysis. Capability Inventory: The skill uses Bash, Write, and Edit tools to perform analysis. Boundary Markers: None explicitly defined in the instructions. Sanitization: None explicitly defined for input profiling data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:13 AM
Security Audit — agent-trust-hub — performance-profiling