python-profiling

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill instructions define a legitimate and structured workflow for performance optimization, emphasizing measurement before and after changes. No malicious patterns, prompt injections, or obfuscation techniques were detected.
  • [COMMAND_EXECUTION]: The skill makes extensive use of the uv CLI to execute benchmarks, profiling tools, and diagnostic commands. These executions are scoped to the project environment and are necessary for the skill's performance-related tasks.
  • [PRIVILEGE_ESCALATION]: The cheatsheet documentation transparently notes that the py-spy tool may require sudo permissions on some systems to access ptrace for process sampling. This is a well-known technical requirement for this specific profiling method and is presented as informative guidance rather than a silent bypass.
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing several well-established Python packages for performance analysis (line-profiler, py-spy, memray, scalene, snakeviz, pytest-benchmark). These are standard community tools and their installation via uv is a routine developer operation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:48 PM
Security Audit — agent-trust-hub — python-profiling