profiling-optimization

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides examples of shell commands using npx to execute diagnostic tools such as 0x, clinic.js, and autocannon. These are established tools for generating flame graphs and performing load testing in the Node.js ecosystem.
  • [DATA_EXFILTRATION]: (Data Exposure Risk) The skill includes functionality to write CPU profiles and database query plans to the local filesystem. While necessary for profiling, users should be aware that these files contain metadata about application logic and data structures.
  • [PROMPT_INJECTION]: (Indirect Surface) The skill demonstrates database profiling and file management that take string inputs for SQL queries and file paths.
  • Ingestion points: Query strings and output file paths in SKILL.md examples.
  • Boundary markers: Not present in the code snippets.
  • Capability inventory: File system writes (fs.writeFileSync), database command execution (pool.query), and shell execution via npx.
  • Sanitization: The database examples utilize parameterized queries (params), which is a best practice for preventing SQL injection, although the high-level query string itself is not sanitized.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 05:37 PM