lighthouse-audit
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads and executes the official Lighthouse CI CLI from the npm registry.
- Evidence: Uses
npx --yes @lhci/cli@latestto run the audit tool at runtime in Step 5 ofSKILL.md. - [COMMAND_EXECUTION]: The skill invokes several shell commands to build the application and process JSON reports.
- Evidence: Commands include
npm run build,npm start, and anode -escript for JSON processing described in the Step-by-Step Protocol andreferences/report-analysis.md. - [PROMPT_INJECTION]: The skill processes data from externally generated reports, creating a surface for indirect prompt injection.
- Ingestion points: Reads
manifest.jsonandlhr-*.jsonfiles produced by the Lighthouse CLI inSKILL.md(Step 6) andreferences/report-analysis.md. - Boundary markers: The protocol lacks explicit delimiters or instructions to treat the report content as untrusted when summarizing findings in the final markdown report.
- Capability inventory: The skill is granted powerful tools including
Bash,Write,Edit, andGrepacross the project workspace. - Sanitization: Audit data is parsed as JSON, but textual fields like audit titles and descriptions are interpolated directly into the agent's output without sanitization or escaping.
Audit Metadata