agent-performance-monitor

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documentation includes operational commands that utilize npx to execute the claude-flow CLI tool for health checks, bottleneck analysis, and metrics collection.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection by processing external data without explicit sanitization.
  • Ingestion points: Data is ingested via mcp.agent_list, mcp.agent_metrics, and mcp.health_check calls (found in SKILL.md).
  • Boundary markers: There are no explicit boundary markers or instructions to ignore embedded commands within the provided metrics processing logic.
  • Capability inventory: The skill includes the capability to execute shell commands via the claude-flow CLI and performs system-level resource tracking (found in SKILL.md).
  • Sanitization: No escaping, validation, or filtering logic is provided for the data retrieved from external agents or system metrics before it is processed or used in analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — agent-performance-monitor