audit-bundle-size
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs
rollup-plugin-visualizervia npm and executessource-map-explorerand@playwright/cliusingnpx. These are standard, well-known development tools for web performance analysis and testing. - [COMMAND_EXECUTION]: The skill executes build commands (e.g.,
npm run build) and shell utilities (find,xargs,ls) to generate and measure bundle sizes and reports. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external web searches (via
firecrawl:firecrawl_search) to research library alternatives, which could potentially contain malicious instructions intended to influence the agent's code modifications. - Ingestion points: Web search results for library alternatives and project configuration files (e.g.,
package.json,vite.config.ts). - Boundary markers: None present; the skill lacks delimiters to separate ingested content from its internal logic.
- Capability inventory: The skill has the capability to modify project configuration files, install new npm packages, and execute shell build scripts.
- Sanitization: No explicit sanitization or validation of the search results is performed before using them to guide code modifications.
Audit Metadata