optimize-web-animations
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill audits external web content which could contain malicious instructions designed to influence the agent. Ingestion points: The agent reads element text and classes via
profileAnimationPageandsamplePerformancePageinreferences/browser-profiling.md. Capability inventory: The skill has high-privilege access includinggit commit,npm run build, andnode_repl.write. Boundary markers and sanitization are absent for the ingested page data.- [DYNAMIC_EXECUTION]: The skill usesplaywright.evaluateto execute JavaScript templates within a browser tab to perform profiling and audit tasks.- [COMMAND_EXECUTION]: The agent executes shell commands includinggitandnpmfor repository management and build verification, representing a significant capability if the agent is misled.
Audit Metadata