lighthouse-audit

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads and executes the official Lighthouse CI CLI from the npm registry.
  • Evidence: Uses npx --yes @lhci/cli@latest to run the audit tool at runtime in Step 5 of SKILL.md.
  • [COMMAND_EXECUTION]: The skill invokes several shell commands to build the application and process JSON reports.
  • Evidence: Commands include npm run build, npm start, and a node -e script for JSON processing described in the Step-by-Step Protocol and references/report-analysis.md.
  • [PROMPT_INJECTION]: The skill processes data from externally generated reports, creating a surface for indirect prompt injection.
  • Ingestion points: Reads manifest.json and lhr-*.json files produced by the Lighthouse CLI in SKILL.md (Step 6) and references/report-analysis.md.
  • Boundary markers: The protocol lacks explicit delimiters or instructions to treat the report content as untrusted when summarizing findings in the final markdown report.
  • Capability inventory: The skill is granted powerful tools including Bash, Write, Edit, and Grep across the project workspace.
  • Sanitization: Audit data is parsed as JSON, but textual fields like audit titles and descriptions are interpolated directly into the agent's output without sanitization or escaping.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 03:50 PM
Security Audit — agent-trust-hub — lighthouse-audit