optimize-web-animations
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from web pages (DOM elements, text content, and attributes) and uses this information to guide its optimization and patching workflow. An attacker could potentially embed malicious instructions in a webpage to influence the agent's actions.
- Ingestion points: The script in
references/browser-profiling.mdextracts text content, class names, and data attributes from the browser's DOM. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard embedded content within the data extracted from the page.
- Capability inventory: The skill possesses the ability to patch local files, run
gitcommands (status, diff, commit), and executenpmscripts (lint, build) as described inSKILL.md. - Sanitization: The profiling scripts use basic string truncation (e.g.,
slice(0, 80)) for extracted text but do not perform security-focused sanitization to prevent prompt injection. - [DYNAMIC_EXECUTION]: The skill generates and executes JavaScript snippets within the browser context using Playwright's
evaluatemethod andnode_replfor performance profiling. - Evidence:
references/browser-profiling.mddefines several complex functions (profileAnimationPage,samplePerformancePage,auditLongSession) that are executed at runtime in the target browser tab. - [COMMAND_EXECUTION]: The skill instructs the agent to execute repository-level commands that could be misused if influenced by an indirect injection.
- Evidence:
SKILL.mdcontains instructions to rungit commit,npm run build, andnpm run lintbased on the results of the performance audit.
Audit Metadata