sota-performance

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional markdown files (SKILL.md and several files in rules/) containing best practices for software performance engineering. It does not contain any executable scripts, tool definitions, or commands that interact with the system or external networks. The analysis of the provided documentation across all 10 threat categories shows no evidence of malicious intent or dangerous patterns.
  • [PROMPT_INJECTION]: No override/bypass markers or attempts to manipulate agent behavior were found. The use of 'IMPORTANT' or 'Critical' is strictly limited to performance severity levels and doctrine.
  • [DATA_EXFILTRATION]: No hardcoded credentials, sensitive file path access, or network operations to untrusted domains were detected. The rules focus on legitimate profiling tools and standard telemetry (e.g., Prometheus, OpenTelemetry).
  • [EXTERNAL_DOWNLOADS]: References to external tools (e.g., py-spy, perf, Criterion) are limited to well-known, industry-standard performance diagnostic and benchmarking software. No remote script execution patterns (e.g., curl | bash) are present.
  • [COMMAND_EXECUTION]: While the skill mentions various CLI tools (e.g., perf, strace, pprof), these are provided as educational references for developers to use during manual profiling and are not executed by the skill itself.
  • [OBFUSCATION]: No obfuscated content, Base64 encoding, or hidden characters were found in the text.
  • [INDIRECT_PROMPT_INJECTION]: The skill does not ingest untrusted runtime data or provide exploitable capabilities that could be targeted via indirect injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 10:16 PM
Security Audit — agent-trust-hub — sota-performance