benchee-profiling

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the benchee package from the official Hex package registry and incorporates official GitHub Actions for workflow automation.
  • Evidence: References to benchee in mix.exs and actions/checkout, actions/upload-artifact in the CI YAML block.
  • [COMMAND_EXECUTION]: The instructions involve executing shell commands to run benchmarks and manage project dependencies via the mix CLI.
  • Evidence: Usage of mix run and mix deps.get within the SKILL.md file.
  • [DYNAMIC_EXECUTION]: The skill uses Elixir's Code.require_file to dynamically load benchmark suite components from local paths.
  • Evidence: Code.require_file("bench/string_benchmark.exs") in bench/suite.exs.
  • [INDIRECT_PROMPT_INJECTION]: The regression script ingests data from local JSON files to perform performance comparisons.
  • Evidence: baseline = File.read!(baseline_file) |> Jason.decode!() in bench/compare_with_baseline.exs.
  • Ingestion points: bench/baseline.json via File.read!.
  • Capability inventory: The skill performs file writes (File.write!) and can fail builds (Mix.raise).
  • Boundary markers: None present.
  • Sanitization: Standard JSON decoding is performed without additional schema validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 11:12 PM
Security Audit — agent-trust-hub — benchee-profiling