optimize-web-animations

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill audits external web content which could contain malicious instructions designed to influence the agent. Ingestion points: The agent reads element text and classes via profileAnimationPage and samplePerformancePage in references/browser-profiling.md. Capability inventory: The skill has high-privilege access including git commit, npm run build, and node_repl.write. Boundary markers and sanitization are absent for the ingested page data.- [DYNAMIC_EXECUTION]: The skill uses playwright.evaluate to execute JavaScript templates within a browser tab to perform profiling and audit tasks.- [COMMAND_EXECUTION]: The agent executes shell commands including git and npm for repository management and build verification, representing a significant capability if the agent is misled.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 01:59 PM
Security Audit — agent-trust-hub — optimize-web-animations