web-perf

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted content from external URLs, which creates a surface for indirect prompt injection attacks where a website's content could attempt to influence the agent's behavior.
  • Ingestion points: The navigate_page(url: "...") tool call in Phase 1 (SKILL.md) and subsequent network/DOM analysis tools ingest external data into the agent's context.
  • Boundary markers: There are no explicit instructions or delimiters defined to separate untrusted website content from the agent's internal instructions.
  • Capability inventory: The skill uses a powerful set of tools including performance_start_trace, list_network_requests, get_network_request, and take_snapshot (SKILL.md, Quick Reference).
  • Sanitization: No specific sanitization or filtering of the ingested DOM or network data is mentioned before processing.
  • [EXTERNAL_DOWNLOADS]: The skill references and encourages the retrieval of information from trusted documentation sources and official developer platforms.
  • The skill instructs the agent to fetch performance thresholds and definitions from web.dev and developer.chrome.com (SKILL.md, Retrieval Sources).
  • It suggests that the user configure the chrome-devtools-mcp package via npx from the NPM registry to enable the skill's functionality (SKILL.md, Verify MCP Tools Available).
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 01:03 PM