performance-thinker
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to analyze, diagnose, and validate user-provided source code (specified for .ts, .js, .sql, and .jsx files in
references/validations.md), which establishes an attack surface for indirect prompt injection. - Ingestion points: The skill ingests untrusted data from user projects and code snippets as input for its profiling and validation logic.
- Boundary markers: The instructions lack explicit boundary markers or directives to the agent to treat embedded content as data only and ignore any instructions found within the code being analyzed.
- Capability inventory: The skill itself does not contain executable scripts or define new tools; it relies on the host agent's native capabilities for file reading and reasoning.
- Sanitization: There are no mechanisms defined to sanitize or escape user-provided content before it is processed by the model.
Audit Metadata