frontend-performance

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill guides the agent in auditing external web pages and performance reports (SKILL.md), creating a surface for indirect prompt injection. \n
  • Ingestion points: Target website source code and PageSpeed/Lighthouse audit reports. \n
  • Boundary markers: None specified to separate external content from internal instructions. \n
  • Capability inventory: The agent is expected to edit project configuration, install packages, and run build commands as documented in SKILL.md and references/nextjs.md. \n
  • Sanitization: No sanitization or validation steps are defined for the external data being audited.\n- [EXTERNAL_DOWNLOADS]: The documentation includes instructions for installing standard development tools such as @next/bundle-analyzer and configuring integrations with well-known services like Google Analytics, Cloudflare, and Stripe. These are routine development practices involving established providers.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 04:18 PM
Security Audit — agent-trust-hub — frontend-performance