javascript-profiling

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for using built-in Node.js CLI flags such as --cpu-prof, --heap-prof, and --trace-gc to generate performance artifacts. These are standard diagnostic tools intended for local developer use.
  • [DYNAMIC_EXECUTION]: The skill demonstrates the use of the node:inspector module to programmatically start and stop CPU profiling within a script. This is a documented use case for the built-in Node.js inspector for fine-grained performance measurement.
  • [DATA_EXFILTRATION]: While the skill mentions taking heap snapshots using v8.writeHeapSnapshot(), which can capture sensitive memory content (secrets, PII), it includes explicit security warnings. It advises users not to capture production heaps without authorization and to ensure secure storage and deletion plans for generated artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 02:00 AM
Security Audit — agent-trust-hub — javascript-profiling