agent-performance-optimizer

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external content such as source code, performance audit results (e.g., Lighthouse JSON), and profiling logs.
  • Ingestion points: Ingests user-provided application code, build artifacts, and diagnostic reports in SKILL.md.
  • Boundary markers: Includes a 'Prompt Defense Baseline' section that instructs the agent to treat external and third-party data as untrusted and to validate input.
  • Capability inventory: Suggests command-line execution for bundle analysis, network auditing, and memory profiling across multiple scripts.
  • Sanitization: Explicitly instructs the agent to sanitize and inspect retrieved data before acting.
  • [EXTERNAL_DOWNLOADS]: The skill suggests using several well-known developer tools via npx, such as lighthouse and bundle-analyzer. These are standard packages used for performance auditing and are consistent with the skill's primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 01:54 PM
Security Audit — agent-trust-hub — agent-performance-optimizer