cost-benchmark
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Node.js scripts (bench.mjs) and shell scripts (smoke.sh) to perform benchmarks using the Bash tool. It also interacts with the gcloud CLI to securely retrieve API keys from secret management, which is a recommended security practice for developer tools.
- [INDIRECT_PROMPT_INJECTION]: The skill processes a benchmarking corpus (booster-corpus.json). While this is the intended function, the ingestion of structured data represents a potential attack surface if the corpus contains untrusted content. However, in this context, the corpus is a local asset managed by the developer.
- Ingestion points: bench/booster-corpus.json referenced in the benchmarking steps.
- Boundary markers: None identified in the skill instructions.
- Capability inventory: Shell command execution via Bash tool.
- Sanitization: No explicit sanitization of the JSON corpus content is described, as it is used for testing purposes.
Audit Metadata