plan-perf-audit

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest performance data from external sources, including websites via tools like Lighthouse and Playwright. This creates a surface where a malicious website could attempt to influence the agent's output. However, the skill explicitly enforces a 'plan-only' mode and requires all findings to be evidenced by measured baselines, which significantly mitigates this risk.
  • [COMMAND_EXECUTION]: The skill suggests the use of standard development tools and commands for performance profiling, such as npm run build -- --analyze and npx lighthouse. These are appropriate for the skill's stated purpose and do not involve arbitrary command injection or dangerous flags.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:48 AM
Security Audit — agent-trust-hub — plan-perf-audit