bolt
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions and reference materials focus entirely on performance optimization and follow established best practices. No malicious patterns, obfuscation, or unauthorized access attempts were identified.
- [EXTERNAL_DOWNLOADS]: The documentation recommends the use of standard development tools and libraries from the npm registry, such as
webpack-bundle-analyzer,clinic, andautocannon. These references are contextually appropriate for performance auditing and do not point to untrusted or malicious sources. - [COMMAND_EXECUTION]: The skill involves executing shell commands for linting, testing, and performance profiling (e.g.,
autocannon -c 100,npx 0x app.js). These commands are standard for the domain and are used within a measurement-first workflow to provide verifiable performance improvements. - [PROMPT_INJECTION]: The skill includes clear operational boundaries, such as requiring baseline metrics before optimization and restricting changes to build configurations or architectural structures. These constraints act as a safeguard against unintended agent behavior.
Audit Metadata