specsfy-specialist-performance-engineering

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of instructional markdown and YAML configuration files. No scripts, executables, or automated tools are provided within the skill package, significantly reducing the potential attack surface.
  • [EXTERNAL_DOWNLOADS]: The skill references several external documentation sources and tools, including Web Vitals, W3C standards, Grafana (k6), PostgreSQL, and React. All referenced URLs target well-known and trusted organizations or official documentation repositories.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external performance data such as Web Vitals, API metrics, and database execution plans. This represents a potential attack surface for indirect prompt injection where maliciously crafted performance logs could attempt to influence agent behavior.
  • Ingestion points: Metrics and logs specified in references/standards.md (LCP, INP, latency, database explain plans).
  • Boundary markers: Not explicitly defined in the instructional text.
  • Capability inventory: The skill provides no built-in capabilities; it guides the user to use external profilers and benchmarking tools.
  • Sanitization: Not applicable as no code is executed by the skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 09:19 PM
Security Audit — agent-trust-hub — specsfy-specialist-performance-engineering