web-performance-audit

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze data from external websites via the navigate_page and take_snapshot tools. This data is untrusted and could contain hidden instructions intended to influence the agent's logic or findings. • Ingestion points: Data from target URLs navigated during the performance audit workflow. • Boundary markers: None identified in the workflow instructions. • Capability inventory: The skill uses tools for performance tracing, network request listing, and DOM snapshotting. • Sanitization: No specific filtering or sanitization steps are defined for the processed web content.
  • [EXTERNAL_DOWNLOADS]: The skill's setup section provides a command for users to install the chrome-devtools-mcp package using npx from the NPM registry. This involves downloading and executing code from a public package repository.
  • [NO_CODE]: The skill consists entirely of markdown documentation and instructions; it does not distribute any executable scripts or binary files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:53 AM
Security Audit — agent-trust-hub — web-performance-audit