bundle-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides templates for executing project-specific analysis tools via pnpm (e.g., bundle-compare, bundle-analyze). These commands are standard for development workflows related to performance and bundle management.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that ingests data from local source files (scratchpad/<fixture>.ts) and generated output (tmp/bundle-stats.txt). While this processing of local data represents an attack surface for indirect instructions, the skill defines narrow, expected operational boundaries for the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 10:08 AM
Security Audit — agent-trust-hub — bundle-analysis