performance-expert

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of documentation, architectural guidelines, and code snippets intended for performance diagnostics. It does not contain any executable scripts that run autonomously or download remote payloads.
  • [COMMAND_EXECUTION]: The skill references standard CLI tools for performance testing and profiling, such as k6, node, and bun. These are prescribed as manual commands for the developer to execute and do not involve suspicious parameters or piped remote execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to discover project context by reading local memory files and source code. While this constitutes an ingestion surface for untrusted data, the skill's instructions are focused on diagnostic output and manual intervention, which adheres to safe practices for developer-centric tools.
  • [DATA_EXPOSURE]: The skill suggests caching and database optimization patterns using standard technologies like Redis and MongoDB. There are no hardcoded credentials or instructions to exfiltrate sensitive environment data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — performance-expert