performance-profiling

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a technical reference for Apple developers. All provided code snippets use standard, documented Apple APIs (e.g., MetricKit, Instruments, os_signpost, and mach_task_basic_info) for their intended purposes.
  • [SAFE]: No obfuscation, data exfiltration, or malicious persistence mechanisms were found. The skill does not attempt to download or execute remote scripts or external packages.
  • [SAFE]: The documentation follows industry-standard security and performance practices, such as recommending the use of static libraries over dynamic frameworks and appropriate memory management techniques.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided performance symptoms to generate profiling plans. While this represents a standard attack surface for indirect prompt injection, there are no exploitable capabilities in the skill scripts that could be leveraged by malicious input, and the impact is considered negligible.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 07:31 AM
Security Audit — agent-trust-hub — performance-profiling