lighthouse-pagespeed-weapon
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides instructions for secure configuration, specifically recommending the use of GitHub Action secrets for sensitive tokens (e.g.,
LHCI_GITHUB_APP_TOKEN) rather than hardcoding credentials. - [SAFE]: Network operations described in the documentation and examples are directed at official and well-known services, including Google's PageSpeed Insights API (
googleapis.com) and reputable performance tracking platforms like Treo and SpeedCurve. - [SAFE]: Package installations mentioned (
@lhci/cli) are standard, well-known development tools within the web performance ecosystem. - [SAFE]: There are no signs of prompt injection, obfuscation, or persistence mechanisms. The skill's behavior and instructions align strictly with its stated purpose as a performance measurement guide.
Audit Metadata