perf-profile

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill defines a legitimate performance profiling workflow. It instructs the agent to analyze the codebase for common performance issues such as unoptimized loops, expensive physics queries, and memory leaks.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to facilitate codebase analysis and search for performance-related patterns, which is consistent with its stated purpose.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes external files from the codebase which could contain malicious instructions.
  • Ingestion points: Reads performance budgets from CLAUDE.md and design documents, and analyzes source code files using Read, Glob, and Grep.
  • Boundary markers: Absent. There are no explicit delimiters or warnings to ignore instructions embedded within the analyzed files.
  • Capability inventory: The skill is allowed access to Read, Glob, Grep, and Bash tools.
  • Sanitization: Absent. The skill does not implement validation or escaping of the content read from the codebase.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 12:11 PM
Security Audit — agent-trust-hub — perf-profile