javascript-profiling
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for using built-in Node.js CLI flags such as
--cpu-prof,--heap-prof, and--trace-gcto generate performance artifacts. These are standard diagnostic tools intended for local developer use. - [DYNAMIC_EXECUTION]: The skill demonstrates the use of the
node:inspectormodule to programmatically start and stop CPU profiling within a script. This is a documented use case for the built-in Node.js inspector for fine-grained performance measurement. - [DATA_EXFILTRATION]: While the skill mentions taking heap snapshots using
v8.writeHeapSnapshot(), which can capture sensitive memory content (secrets, PII), it includes explicit security warnings. It advises users not to capture production heaps without authorization and to ensure secure storage and deletion plans for generated artifacts.
Audit Metadata