performance-profiling

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/lighthouse_audit.py script invokes the lighthouse CLI tool. It correctly utilizes subprocess.run with a list of arguments rather than a shell string, which is the recommended practice for preventing shell injection attacks.
  • [EXTERNAL_DOWNLOADS]: The skill references the lighthouse CLI package. Lighthouse is a well-known, industry-standard tool for performance auditing maintained by Google, and the installation instructions point to the official NPM registry.
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with external website content via Lighthouse audits, which represents a potential attack surface.
  • Ingestion points: Data is fetched from user-provided URLs in scripts/lighthouse_audit.py.
  • Boundary markers: The script uses JSON parsing and selectively extracts only specific performance metrics (performance, accessibility, best-practices, seo).
  • Capability inventory: The skill is limited to running the performance audit and returning scores.
  • Sanitization: The script converts raw data into numeric scores and returns static summary strings, ensuring that untrusted text from the target website does not reach the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — performance-profiling