rspeedy-bundle-size
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides scripts and documentation for legitimate developer optimization tasks. All technical operations, such as build profiling and code analysis, are performed locally within the project context and align with standard software development practices.
- [SAFE]: External resource references point exclusively to official and well-known repositories belonging to reputable organizations, such as ByteDance's Web Infra Dev group and Microsoft's Rushstack project. These are used for library discovery and best practice references.
- [INDIRECT_PROMPT_INJECTION]: The skill features analysis tools (
scan-levers.mjs,mt-leak-analyzer.mjs,mt-cutpoint-analyzer.mjs) that ingest local project source code and build artifacts as input. - Ingestion points: User-provided project directories and build artifacts like
main-thread.jsorstats.jsonare read viafs.readFileSyncacross multiple analysis scripts. - Boundary markers: The scripts do not implement explicit boundary markers or "ignore" instructions for the ingested content, as they are technical diagnostic tools intended for local execution by a developer.
- Capability inventory: The tools utilize standard file system read access (
fs.readFileSync) and standard output (console.log) without performing network operations, file writes, or privilege escalation. - Sanitization: The scripts do not perform sanitization of the input files, as they are designed for internal technical analysis of code structures.
Audit Metadata