third-party-bloat

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs its stated function of web performance auditing using official browser inspection tools.
  • [PROMPT_INJECTION]: While the skill ingests untrusted data from navigated URLs (network request metadata), the risk of indirect prompt injection is minimal as the instructions are limited to classification and grouping of domains.
  • Ingestion points: Network request data retrieved via mcp__playwright__browser_network_requests in SKILL.md.
  • Boundary markers: Absent.
  • Capability inventory: Limited to browser navigation and network inspection tools.
  • Sanitization: None specified for the domain processing logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 04:07 PM
Security Audit — agent-trust-hub — third-party-bloat