native-app-performance
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocessto invoke standard macOS developer utilities such asxctrace,otool,vmmap, andatos. These calls are implemented using argument lists, which is a secure practice to prevent shell injection. - [DATA_EXPOSURE]: Performance traces and extracted XML data are stored and processed locally in the
/tmp/directory. No network operations or external data exfiltration patterns were identified. - [SAFE]: The scripts are clearly written for the stated purpose of performance analysis. They use standard Python and Bash practices without any signs of obfuscation, persistence mechanisms, or unauthorized privilege escalation.
Audit Metadata