performance

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to utilize standard development and profiling tools through the command line, such as npm run build, npx lighthouse, and source-map-explorer. It also includes a verify.sh script that uses shell utilities like find, grep, sed, and awk to perform static linting of budget files.
  • [EXTERNAL_DOWNLOADS]: The skill references and recommends the installation of well-known libraries and tools from the npm registry, including web-vitals, @next/bundle-analyzer, and lighthouse for performance measurement.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests performance metrics and reports which are derived from external websites and third-party tool outputs.
  • Ingestion points: Performance data from Lighthouse reports, Chrome DevTools traces, and RUM (Real User Monitoring) beacons generated from analyzed web pages.
  • Boundary markers: No explicit delimiters are suggested for the agent to separate performance data from instructional context.
  • Capability inventory: The skill utilizes shell command execution via recommended profiling tools and the included budget verification script.
  • Sanitization: No explicit sanitization or filtering of external tool output is documented.
  • [DYNAMIC_EXECUTION]: The scripts/verify.sh script performs dynamic parsing of JSON files using jq and grep to extract numeric thresholds for comparison via awk. The script implements safe parsing logic that restricts extracted values to numeric characters, preventing shell injection during value comparison.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:57 AM
Security Audit — agent-trust-hub — performance