performance-optimization

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a technical assistant for performance engineering. It contains legitimate code snippets for profiling, caching, and bundle optimization. No malicious patterns, obfuscation, or data exfiltration attempts were detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a standard vulnerability surface as it is designed to analyze user-provided code and performance data. However, it lacks dangerous capabilities and includes grounding instructions to follow specific reference files.
  • Ingestion points: User-supplied code snippets, performance logs, and optimization requests (e.g., "slow page load").
  • Boundary markers: The "Reference System Usage" section in SKILL.md explicitly instructs the agent to ground responses in the provided reference files and correct users if they conflict with these sources.
  • Capability inventory: The skill provides advice, diagnostic commands (e.g., node --prof, cProfile), and code examples. It does not invoke tools for automated file modification or network communication.
  • Sanitization: Not applicable as the skill primarily outputs text-based recommendations and does not execute user data in a sensitive context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:15 PM
Security Audit — agent-trust-hub — performance-optimization