performance-profiling

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/lighthouse_audit.py uses subprocess.run to call the lighthouse CLI. It correctly passes arguments as a list rather than a shell string, which prevents command injection vulnerabilities from the user-provided URL.
  • [EXTERNAL_DOWNLOADS]: The skill requires the lighthouse package from the NPM registry. This is a well-known, trusted utility maintained by Google for web performance auditing.
  • [DATA_EXPOSURE]: The script uses tempfile.NamedTemporaryFile and ensures the temporary report file is deleted (os.unlink) immediately after reading, minimizing the footprint of data on the local filesystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 11:32 PM
Security Audit — agent-trust-hub — performance-profiling