skills/johnlindquist/claude/perf/Gen Agent Trust Hub

perf

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs 'lighthouse' via npm and 'google-generativeai' via pip. Both are well-known tools from trusted organizations (Google/Open Source) and do not pose a direct security risk.
  • [COMMAND_EXECUTION]: The skill uses various system commands such as 'node', 'time', 'git', and 'cat' to gather performance metrics and manage code state during benchmarking. These operations are restricted to the local environment and the user's project files.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads local source code (e.g., 'cat src/*.ts') and sends it to the Gemini LLM for performance analysis. While intended for optimization, this pattern creates a vulnerability surface where malicious content embedded in the source files could potentially influence the AI's analysis or instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:25 PM
Security Audit — agent-trust-hub — perf