ux-performance

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists entirely of instructional markdown files providing guidance on performance optimization. It does not contain scripts, binary files, or executable commands that could pose a threat to the execution environment.
  • [EXTERNAL_DOWNLOADS]: The documentation references established and trusted resources from organizations such as Google (web.dev, developer.chrome.com, GoogleChrome/lighthouse-ci), Microsoft (playwright.dev), React (react.dev), and Grafana (grafana.com). These references are used for standard technical documentation and established performance tooling.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process external data sources like performance traces, telemetry, and Lighthouse reports. While this presents an ingestion surface for untrusted data, the skill lacks dangerous sinks (such as arbitrary command execution or sensitive file writes) that could be triggered by malicious data content, resulting in no identifiable risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 02:00 AM
Security Audit — agent-trust-hub — ux-performance