performance-profiling

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/lighthouse_audit.py invokes the lighthouse command-line tool. It uses subprocess.run with an argument list, which is the recommended security practice to prevent shell injection vulnerabilities.
  • [EXTERNAL_DOWNLOADS]: The skill documentation identifies a dependency on the lighthouse package, which is a well-known and trusted web auditing tool from the Chrome team, intended to be installed via npm.
  • [SAFE]: No malicious patterns such as prompt injection, credential exposure, or data exfiltration were detected. The script performs legitimate performance measurement tasks and handles temporary audit data securely by cleaning up generated files.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 07:46 AM
Security Audit — agent-trust-hub — performance-profiling