skill-performance-audit

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Static Analysis Logic: The skill defines a set of rules for identifying performance bottlenecks through pattern matching in source code. It does not execute the code it analyzes.\n- [SAFE]: Absence of Malicious Patterns: No evidence of prompt injection, data exfiltration, or persistence mechanisms was found within the skill instructions or reference files.\n- [SAFE]: Credential Handling: While the skill mentions configuration strings like DATABASE_URL, it does so in the context of identifying performance-related parameters (e.g., connection pool limits and timeouts). It does not attempt to extract, store, or exfiltrate credentials.\n- [SAFE]: Instructional Integrity: The skill instructions focus on systematic auditing and reporting. It includes explicit 'What We Do NOT Do' guidelines that prevent the agent from making speculative or unfounded recommendations.\n- [SAFE]: Indirect Prompt Injection Surface: The skill processes user-provided source files, which is a potential entry point for indirect prompt injection. However, the risk is negligible because the skill's capabilities are limited to textual analysis and reporting without access to sensitive tools or network writes.\n
  • Ingestion points: User-specified project source directory.\n
  • Boundary markers: Not explicitly defined in the prompt logic.\n
  • Capability inventory: Reading files and generating text-based audit reports.\n
  • Sanitization: Not identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 01:22 PM
Security Audit — agent-trust-hub — skill-performance-audit