plan-perf-audit
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest performance data from external sources, including websites via tools like Lighthouse and Playwright. This creates a surface where a malicious website could attempt to influence the agent's output. However, the skill explicitly enforces a 'plan-only' mode and requires all findings to be evidenced by measured baselines, which significantly mitigates this risk.
- [COMMAND_EXECUTION]: The skill suggests the use of standard development tools and commands for performance profiling, such as
npm run build -- --analyzeandnpx lighthouse. These are appropriate for the skill's stated purpose and do not involve arbitrary command injection or dangerous flags.
Audit Metadata