performance-lighthouse-runner

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to assist with frontend development tasks, including processing code and configurations (e.g., React, Vue, CSS) which may originate from untrusted sources.
  • Ingestion points: User-provided requests and files related to performance optimization and web development patterns (SKILL.md).
  • Boundary markers: The skill lacks explicit instructions for the agent to use delimiters or ignore instructions embedded within the processed data.
  • Capability inventory: The skill is configured with access to powerful tools including Bash(cmd:*), Write, and Edit (SKILL.md).
  • Sanitization: No explicit sanitization or validation steps for external content are defined in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 10:31 PM
Security Audit — agent-trust-hub — performance-lighthouse-runner