profiling-optimization
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides examples of shell commands using
npxto execute diagnostic tools such as0x,clinic.js, andautocannon. These are established tools for generating flame graphs and performing load testing in the Node.js ecosystem. - [DATA_EXFILTRATION]: (Data Exposure Risk) The skill includes functionality to write CPU profiles and database query plans to the local filesystem. While necessary for profiling, users should be aware that these files contain metadata about application logic and data structures.
- [PROMPT_INJECTION]: (Indirect Surface) The skill demonstrates database profiling and file management that take string inputs for SQL queries and file paths.
- Ingestion points: Query strings and output file paths in
SKILL.mdexamples. - Boundary markers: Not present in the code snippets.
- Capability inventory: File system writes (
fs.writeFileSync), database command execution (pool.query), and shell execution vianpx. - Sanitization: The database examples utilize parameterized queries (
params), which is a best practice for preventing SQL injection, although the high-levelquerystring itself is not sanitized.
Audit Metadata