react-performance-optimizer
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests local source files for performance auditing, which creates an attack surface where malicious content in those files could influence the agent via the generated reports.
- Ingestion points: The
scripts/performance_audit.tsscript reads the content of all.tsxand.jsxfiles within a user-specified directory. - Boundary markers: Absent. The script reads file contents directly for regex matching and reporting without using delimiters or instructions to the agent to ignore embedded content.
- Capability inventory: The skill is configured with
Read,Write,Edit, andBash(npm:*)tools. Thescripts/bundle_analyzer.shscript performs file writes and package installations, whilescripts/performance_audit.tsperforms file system reads. - Sanitization: Absent. The auditing script performs direct regex matching on raw file content and includes portions of the matched lines in the output report provided to the agent.
- [EXTERNAL_DOWNLOADS]: The skill dynamically installs established performance analysis packages from the NPM registry as needed during the analysis process.
- Evidence:
scripts/bundle_analyzer.shincludes logic to install@next/bundle-analyzer,rollup-plugin-visualizer,source-map-explorer, andwebpack-bundle-analyzerif they are not detected in the project. - [COMMAND_EXECUTION]: The skill utilizes shell commands to perform project builds, dependency installation, and bundle analysis.
- Evidence:
scripts/bundle_analyzer.shexecutesnpm install,npm run build, andnpx webpackto generate performance statistics.
Audit Metadata