audit-bundle-size

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs rollup-plugin-visualizer via npm and executes source-map-explorer and @playwright/cli using npx. These are standard, well-known development tools for web performance analysis and testing.
  • [COMMAND_EXECUTION]: The skill executes build commands (e.g., npm run build) and shell utilities (find, xargs, ls) to generate and measure bundle sizes and reports.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external web searches (via firecrawl:firecrawl_search) to research library alternatives, which could potentially contain malicious instructions intended to influence the agent's code modifications.
  • Ingestion points: Web search results for library alternatives and project configuration files (e.g., package.json, vite.config.ts).
  • Boundary markers: None present; the skill lacks delimiters to separate ingested content from its internal logic.
  • Capability inventory: The skill has the capability to modify project configuration files, install new npm packages, and execute shell build scripts.
  • Sanitization: No explicit sanitization or validation of the search results is performed before using them to guide code modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 05:12 AM
Security Audit — agent-trust-hub — audit-bundle-size