workspace-performance-audit
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides the agent with a series of shell commands (e.g.,
ls,cat,grep,npx) and database queries (e.g.,db.collection.stats()) to perform workspace discovery and collect performance metrics. - [INDIRECT_PROMPT_INJECTION]: A vulnerability surface exists because the skill ingests untrusted data from the monorepo, including
package.jsonfiles, source code, and outputs from external diagnostic tools. - Ingestion points: Workspace configuration files (
package.json), application source code, and results from Lighthouse and MongoDB profiler tools. - Boundary markers: Not explicitly defined in the provided orchestration guide for separating tool outputs from agent instructions.
- Capability inventory: Shell execution (
ls,cat,npx), database command execution, and file system write operations to the.agents/memory/directory. - Sanitization: No explicit sanitization or validation of external content is described in the audit guide.
- [EXTERNAL_DOWNLOADS]: The skill leverages the
npxcommand to download and execute performance analysis tools such as@next/bundle-analyzer,lighthouse, anddepcheckfrom the NPM registry.
Audit Metadata