python-memory-profiling

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard developer workflows for performance and memory analysis using established tools (tracemalloc, memray, guppy3, psutil, filprofiler).
  • [EXTERNAL_DOWNLOADS]: The skill documents installation of Python packages via pip install -r requirements.txt. The listed dependencies (guppy3, memray, psutil, filprofiler) are well-known, legitimate profiling libraries. These are standard development dependencies and do not represent a security risk.
  • [COMMAND_EXECUTION]: The skill includes instructions for running shell commands and Python scripts (e.g., python run_tracemalloc.py, memray run program.py). These commands are scoped to the project's own files (python/program.py) and standard tool CLIs, representing normal development behavior.
  • [DATA_EXFILTRATION]: While the skill mentions the program performs live HTTP requests to Wikipedia, this is documented as the primary function of the example program being profiled. There are no patterns of sensitive data (credentials, SSH keys) being accessed or sent to unauthorized external domains.
  • [METADATA_POISONING]: The metadata fields (name, description) accurately reflect the content of the skill and do not contain deceptive instructions or injection attempts.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 02:00 AM
Security Audit — agent-trust-hub — python-memory-profiling