perf-profile
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill defines a legitimate performance profiling workflow. It instructs the agent to analyze the codebase for common performance issues such as unoptimized loops, expensive physics queries, and memory leaks.
- [COMMAND_EXECUTION]: The skill utilizes the Bash tool to facilitate codebase analysis and search for performance-related patterns, which is consistent with its stated purpose.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes external files from the codebase which could contain malicious instructions.
- Ingestion points: Reads performance budgets from
CLAUDE.mdand design documents, and analyzes source code files usingRead,Glob, andGrep. - Boundary markers: Absent. There are no explicit delimiters or warnings to ignore instructions embedded within the analyzed files.
- Capability inventory: The skill is allowed access to
Read,Glob,Grep, andBashtools. - Sanitization: Absent. The skill does not implement validation or escaping of the content read from the codebase.
Audit Metadata