skills/simota/agent-skills/bolt/Gen Agent Trust Hub

bolt

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses industry-standard and well-known profiling tools such as Lighthouse, clinic.js, 0x, and autocannon, which are standard in the web development ecosystem for performance measurement.
  • [SAFE]: External references in the documentation target established technical blogs (e.g., DeveloperWay, Stackify) and official GitHub repositories for performance libraries (e.g., criterion.rs, async-profiler).
  • [SAFE]: The skill emphasizes a 'Measure → Identify → Optimize → Verify' workflow, ensuring that code changes are driven by empirical data and verified against baselines, which reduces the risk of unintended side effects.
  • [SAFE]: Guidance for handling secrets (e.g., using .env files) follows secure development practices, and no hardcoded credentials or sensitive file paths were detected.
  • [SAFE]: The skill's suggested library migrations (e.g., moment → date-fns, axios → fetch) are common, secure, and size-efficient alternatives aimed at reducing the attack surface and bundle weight.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:48 PM
Security Audit — agent-trust-hub — bolt