core-web-vitals
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell command (
ls) to inspect multiple local directories associated with AI agent skills to determine if recommended companion tools are installed on the user's system. - [DATA_EXFILTRATION]: Documentation within the skill provides code snippets for sending real-user monitoring (RUM) data to external endpoints, such as Google's CrUX API, custom analytics backends, and Slack webhooks for performance alerting.
- [EXTERNAL_DOWNLOADS]: The skill references and provides installation instructions for various legitimate third-party libraries and tools from established providers, including Google's web-vitals, Lighthouse CI, and several web framework optimization packages.
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by ingesting and processing data from external sources like the Chrome User Experience Report (CrUX) API without utilizing explicit boundary markers or sanitization logic to handle the external content.
Audit Metadata