review-perf
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute performance benchmark commands (specifically a
benchcommand) if defined in the project's 'agent guide'. This is an intended and documented capability for gathering performance metrics during the audit. - [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests and acts upon data from the codebase being audited. Ingestion points: Audited repository diffs and the 'project agent guide'. Boundary markers: None defined to isolate instructions within the project guide. Capability inventory: Execution of local shell commands via the benchmark process. Sanitization: No explicit validation or filtering of the commands extracted from the project guide before execution.
Audit Metadata