audit-agent-speed

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides detailed PowerShell and Shell commands in Phase 0 to monitor CPU usage. These commands utilize standard system tools such as Get-Counter, Get-CimInstance, and ps. While these commands interface with the operating system, they are used strictly for performance measurement as per the skill's primary purpose.
  • [DYNAMIC_EXECUTION]: The provided scripts/stop-typecheck.mjs script acts as a dynamic wrapper for project-defined scripts. It uses spawnSync to execute commands defined in the local package.json (e.g., npm run typecheck). The script includes a safety check that validates the requested script name exists in the package.json before execution, mitigating risks of arbitrary command injection through the script argument.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local configuration files (package.json, .claude/settings.json) and git command outputs. While this represents an attack surface for indirect prompt injection if those files contained malicious instructions, the skill's behavior is restricted to performance inventory and reporting, with clear instructions for the agent to seek user approval before applying fixes.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 05:41 AM
Security Audit — agent-trust-hub — audit-agent-speed