benchmark
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external URLs and API endpoints (ingestion points) to calculate performance metrics (SKILL.md). It does not include explicit boundary markers or sanitization for external content. The skill's capabilities include browser navigation, HTTP requests, local file writing to the .ecc/benchmarks/ directory, and execution of local build tools. This attack surface is inherent to its primary purpose and limited by its focus on technical metrics.- [COMMAND_EXECUTION]: The skill invokes standard development tools such as Docker, TypeScript compilers, and linters to establish build performance baselines. These operations are expected within the context of a performance benchmarking tool.- [DATA_EXPOSURE]: Performance data is recorded and stored locally in the .ecc/benchmarks/ directory for regression tracking, representing normal behavior for this skill.
Audit Metadata