eg-web-performance-audit
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external web performance reports and data, which constitutes an ingestion surface for untrusted content. (1) Ingestion points: External URLs and performance reports provided by the user during the audit process (mentioned in SKILL.md workflow). (2) Capability inventory: The skill provides instructions and references but contains no code, subprocess calls, or network automation tools. (3) Boundary markers: None explicitly defined to delimit external data. (4) Sanitization: Not applicable as the skill does not include processing code.
- [SAFE]: No malicious patterns, command executions, or credential exposures were detected. The resources and tools referenced, such as PageSpeed Insights, Lighthouse, and WebPageTest, are established industry standards for web performance monitoring.
Audit Metadata