react-performance-optimizer

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests local source files for performance auditing, which creates an attack surface where malicious content in those files could influence the agent via the generated reports.
  • Ingestion points: The scripts/performance_audit.ts script reads the content of all .tsx and .jsx files within a user-specified directory.
  • Boundary markers: Absent. The script reads file contents directly for regex matching and reporting without using delimiters or instructions to the agent to ignore embedded content.
  • Capability inventory: The skill is configured with Read, Write, Edit, and Bash(npm:*) tools. The scripts/bundle_analyzer.sh script performs file writes and package installations, while scripts/performance_audit.ts performs file system reads.
  • Sanitization: Absent. The auditing script performs direct regex matching on raw file content and includes portions of the matched lines in the output report provided to the agent.
  • [EXTERNAL_DOWNLOADS]: The skill dynamically installs established performance analysis packages from the NPM registry as needed during the analysis process.
  • Evidence: scripts/bundle_analyzer.sh includes logic to install @next/bundle-analyzer, rollup-plugin-visualizer, source-map-explorer, and webpack-bundle-analyzer if they are not detected in the project.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands to perform project builds, dependency installation, and bundle analysis.
  • Evidence: scripts/bundle_analyzer.sh executes npm install, npm run build, and npx webpack to generate performance statistics.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:08 PM
Security Audit — agent-trust-hub — react-performance-optimizer