web-performance-audit
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze data from external websites via the
navigate_pageandtake_snapshottools. This data is untrusted and could contain hidden instructions intended to influence the agent's logic or findings. • Ingestion points: Data from target URLs navigated during the performance audit workflow. • Boundary markers: None identified in the workflow instructions. • Capability inventory: The skill uses tools for performance tracing, network request listing, and DOM snapshotting. • Sanitization: No specific filtering or sanitization steps are defined for the processed web content. - [EXTERNAL_DOWNLOADS]: The skill's setup section provides a command for users to install the
chrome-devtools-mcppackage usingnpxfrom the NPM registry. This involves downloading and executing code from a public package repository. - [NO_CODE]: The skill consists entirely of markdown documentation and instructions; it does not distribute any executable scripts or binary files.
Audit Metadata