ln-44-performance-optimizer
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to research and ingest external primary sources such as official documentation, release notes, and specifications to verify hypotheses and modify code. This creates a vulnerability surface where malicious content in external documents could influence the agent's actions.
- Ingestion points: The agent is directed to perform "primary-source web research" and read "Official documentation, release notes, and specifications" (SKILL.md, Tool Routing table).
- Boundary markers: The skill lacks instructions to use delimiters or ignore embedded instructions when reading these external sources.
- Capability inventory: The agent has the authority to edit repository files (KEEP, ADD, UPDATE, DELETE in Checklist Section 4) and execute system commands for benchmarking and testing.
- Sanitization: No sanitization or validation of the external content is required before it is used to inform code changes.
- [COMMAND_EXECUTION]: The skill requires the use of several powerful tool categories, including Git status/diff, profilers, tracing tools, and OS-level metrics. It specifically directs the agent to run "reproducible command[s]" and "repository-defined tests, build, lint, type, and smoke commands" (SKILL.md, Tool Routing). While intended for performance analysis, this constitutes a significant command execution capability.
Audit Metadata