benchee-profiling
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes the benchee package from the official Hex package registry and incorporates official GitHub Actions for workflow automation.
- Evidence: References to benchee in mix.exs and actions/checkout, actions/upload-artifact in the CI YAML block.
- [COMMAND_EXECUTION]: The instructions involve executing shell commands to run benchmarks and manage project dependencies via the mix CLI.
- Evidence: Usage of mix run and mix deps.get within the SKILL.md file.
- [DYNAMIC_EXECUTION]: The skill uses Elixir's Code.require_file to dynamically load benchmark suite components from local paths.
- Evidence: Code.require_file("bench/string_benchmark.exs") in bench/suite.exs.
- [INDIRECT_PROMPT_INJECTION]: The regression script ingests data from local JSON files to perform performance comparisons.
- Evidence: baseline = File.read!(baseline_file) |> Jason.decode!() in bench/compare_with_baseline.exs.
- Ingestion points: bench/baseline.json via File.read!.
- Capability inventory: The skill performs file writes (File.write!) and can fail builds (Mix.raise).
- Boundary markers: None present.
- Sanitization: Standard JSON decoding is performed without additional schema validation.
Audit Metadata