widget-performance-analyzer

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses local command-line tools (grep, find, wc, flutter analyze) to perform read-only static analysis on the lib/ directory. These commands use hardcoded search patterns and do not incorporate user-provided input into the shell execution, mitigating command injection risks.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data by reading Dart source files from the project being audited. This constitutes a vulnerability surface, but the risk is assessed as safe because the skill performs specific structural analysis and does not provide an execution environment for the ingested data.
  • Ingestion points: Reads .dart files recursively within the lib/ directory and main.dart (SKILL.md).
  • Boundary markers: None present; the skill relies on the agent's instructions to produce a structured performance report.
  • Capability inventory: Limited to local search and analysis tools (grep, find, flutter analyze). No network operations, file-writing, or dynamic code execution capabilities are present.
  • Sanitization: None, as the skill identifies static code patterns rather than executing the code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:24 PM
Security Audit — agent-trust-hub — widget-performance-analyzer