perf-profiler

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides high-level instructional guidelines for performance analysis. It does not contain any executable code, scripts, or automated network operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves processing external data such as performance traces, logs, and codebases. While this creates a theoretical surface for indirect prompt injection, the skill specifically instructs the agent to differentiate between measured evidence and static inference, and includes safety boundaries to protect sensitive production data. The instructions serve to improve the reliability of the analysis rather than create a vulnerability.
  • [COMMAND_EXECUTION]: The skill mentions using tools like profilers, benchmarks, and database execution plans. However, it explicitly states that all production operations, benchmarks, and configuration changes require clear user authorization. No malicious or unauthorized commands are present in the skill definition.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 09:13 AM
Security Audit — agent-trust-hub — perf-profiler