performance
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to utilize standard development and profiling tools through the command line, such as
npm run build,npx lighthouse, andsource-map-explorer. It also includes averify.shscript that uses shell utilities likefind,grep,sed, andawkto perform static linting of budget files. - [EXTERNAL_DOWNLOADS]: The skill references and recommends the installation of well-known libraries and tools from the npm registry, including
web-vitals,@next/bundle-analyzer, andlighthousefor performance measurement. - [INDIRECT_PROMPT_INJECTION]: The skill ingests performance metrics and reports which are derived from external websites and third-party tool outputs.
- Ingestion points: Performance data from Lighthouse reports, Chrome DevTools traces, and RUM (Real User Monitoring) beacons generated from analyzed web pages.
- Boundary markers: No explicit delimiters are suggested for the agent to separate performance data from instructional context.
- Capability inventory: The skill utilizes shell command execution via recommended profiling tools and the included budget verification script.
- Sanitization: No explicit sanitization or filtering of external tool output is documented.
- [DYNAMIC_EXECUTION]: The
scripts/verify.shscript performs dynamic parsing of JSON files usingjqandgrepto extract numeric thresholds for comparison viaawk. The script implements safe parsing logic that restricts extracted values to numeric characters, preventing shell injection during value comparison.
Audit Metadata