performance-thinker

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to analyze, diagnose, and validate user-provided source code (specified for .ts, .js, .sql, and .jsx files in references/validations.md), which establishes an attack surface for indirect prompt injection.
  • Ingestion points: The skill ingests untrusted data from user projects and code snippets as input for its profiling and validation logic.
  • Boundary markers: The instructions lack explicit boundary markers or directives to the agent to treat embedded content as data only and ignore any instructions found within the code being analyzed.
  • Capability inventory: The skill itself does not contain executable scripts or define new tools; it relies on the host agent's native capabilities for file reading and reasoning.
  • Sanitization: There are no mechanisms defined to sanitize or escape user-provided content before it is processed by the model.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 04:54 PM
Security Audit — agent-trust-hub — performance-thinker