perf-profile

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes a dynamic context injection pattern (!bash ...) to execute a local script named yaml-helper.sh at load time. This execution is used to resolve project-specific configuration keys such as performance.enforce and automation. The operation is limited to local environment variables and project files.
  • [COMMAND_EXECUTION]: The skill invokes the Bash tool to source local helper scripts and retrieve performance budget data. The skill's configuration in the frontmatter explicitly restricts the Bash tool to a specific script path (*/.claude/skills/perf-profile/../../hooks/yaml-helper.sh), which significantly reduces the risk of arbitrary command execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external artifacts including source code, profiler outputs, and test results, creating an indirect prompt injection surface.
  • Ingestion points: SKILL.md indicates the skill reads data files, prior reports, profiler output, test results, and source code.
  • Boundary markers: No explicit boundary markers or "ignore instructions" delimiters are specified for the processed content.
  • Capability inventory: The skill has access to Read, Glob, Grep, and a restricted Bash configuration.
  • Sanitization: There is no evidence of sanitization or filtering applied to the external content before it is processed by the model.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:51 PM
Security Audit — agent-trust-hub — perf-profile