node
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends several widely-used and reputable Node.js libraries and tools to implement best practices, including 'pino' for logging, 'zod' for validation, 'autocannon' for benchmarking, and various utilities from the Fastify ecosystem. These are standard community resources.
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates workflows where an AI agent may ingest external diagnostic data, such as markdown reports from profiling tools like '@platformatic/flame' or test output logs. This constitutes a potential ingestion surface for untrusted data, although the primary usage is for developer analysis.
- Ingestion points: Profiling reports and test output logs (SKILL.md, rules/profiling.md).
- Boundary markers: None identified for external reports.
- Capability inventory: The skill primarily provides documentation and code patterns; it does not include scripts that execute arbitrary commands or perform network operations on ingested data.
- Sanitization: Not applicable as the skill serves as a reference guide.
Audit Metadata