binary-size-analysis
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- External Resource Download: Fetches the bloaty analysis tool from Google's GitHub repository. This is a common practice for specialized analysis tasks, utilizing a well-known tool for per-section binary comparison.
- Command Execution: The skill performs build operations using standard tools like git, cmake, and ninja. These are necessary components of the binary size measurement process, which requires checking out and compiling specific versions of the codebase.
- Indirect Prompt Injection Surface: The skill reads commit subjects from the git history to generate its reports. As a general safety practice, users should be aware that these messages are ingested as data. While they are primarily used for reporting, it is always a best practice to perform automated analysis on repositories from trusted sources.
Audit Metadata