audit-agent-speed
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides detailed PowerShell and Shell commands in Phase 0 to monitor CPU usage. These commands utilize standard system tools such as
Get-Counter,Get-CimInstance, andps. While these commands interface with the operating system, they are used strictly for performance measurement as per the skill's primary purpose. - [DYNAMIC_EXECUTION]: The provided
scripts/stop-typecheck.mjsscript acts as a dynamic wrapper for project-defined scripts. It usesspawnSyncto execute commands defined in the localpackage.json(e.g.,npm run typecheck). The script includes a safety check that validates the requested script name exists in thepackage.jsonbefore execution, mitigating risks of arbitrary command injection through the script argument. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local configuration files (
package.json,.claude/settings.json) andgitcommand outputs. While this represents an attack surface for indirect prompt injection if those files contained malicious instructions, the skill's behavior is restricted to performance inventory and reporting, with clear instructions for the agent to seek user approval before applying fixes.
Audit Metadata