agent-performance-optimizer
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external content such as source code, performance audit results (e.g., Lighthouse JSON), and profiling logs.
- Ingestion points: Ingests user-provided application code, build artifacts, and diagnostic reports in SKILL.md.
- Boundary markers: Includes a 'Prompt Defense Baseline' section that instructs the agent to treat external and third-party data as untrusted and to validate input.
- Capability inventory: Suggests command-line execution for bundle analysis, network auditing, and memory profiling across multiple scripts.
- Sanitization: Explicitly instructs the agent to sanitize and inspect retrieved data before acting.
- [EXTERNAL_DOWNLOADS]: The skill suggests using several well-known developer tools via npx, such as lighthouse and bundle-analyzer. These are standard packages used for performance auditing and are consistent with the skill's primary purpose.
Audit Metadata