application-performance-performance-optimization

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill implements a pattern susceptible to indirect prompt injection by interpolating the user-controlled $ARGUMENTS variable directly into instructions for various specialized sub-agents (e.g., performance-engineer, database-optimizer). * Ingestion points: $ARGUMENTS variable in SKILL.md. * Boundary markers: Not present; user input is not delimited from instructions. * Capability inventory: Sub-agents have access to tools for performance profiling, database management, and load testing. * Sanitization: No validation or filtering is applied to the input variable.
  • [DATA_EXFILTRATION]: The skill instructs sub-agents to generate and analyze sensitive data artifacts, specifically memory heap dumps and database slow query logs. These sources can contain sensitive information such as credentials, session tokens, or personally identifiable information (PII).
  • [SAFE]: The skill references and integrates with well-known and trusted observability and performance services, including DataDog, New Relic, OpenTelemetry, Grafana, and PagerDuty.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 06:26 PM