performance-regression-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external performance data, including baseline/candidate results, metrics, and traces, which could potentially contain malicious instructions. While the skill instructs the agent to separate facts from assumptions and link conclusions to evidence, it lacks explicit boundary markers or sanitization for interpolated external data.
  • Ingestion points: Ingests performance evidence, workload configurations, and metrics as described in prompts/performance-regression-analysis.md.
  • Boundary markers: Missing specific delimiters for external input, though it mandates a logical separation of facts and assumptions in the output.
  • Capability inventory: The skill primarily generates analytical reports and validation plans; no scripts or tools for automated execution were found in the provided files.
  • Sanitization: No explicit sanitization or filtering of external content before processing is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:26 AM
Security Audit — agent-trust-hub — performance-regression-analysis