first-contentful-paint

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill content is educational and focuses on frontend performance optimization (First Contentful Paint). It provides standard code snippets for Next.js, React, and general web development without any malicious intent or commands.
  • [EXTERNAL_DOWNLOADS]: The skill references resources and CDN origins from well-known services.
  • References fonts.googleapis.com and fonts.gstatic.com for font preconnecting.
  • Links to frontendchecklist.io for further documentation and rule references.
  • [PROMPT_INJECTION]: The skill involves an indirect prompt injection surface by instructing the agent to analyze external project data.
  • Ingestion points: The agent is tasked with reviewing project routes, assets, and loading behavior (SKILL.md).
  • Boundary markers: None present to separate untrusted code analysis from the agent's instructions.
  • Capability inventory: The skill requires read-access to files and measurement tools (Lighthouse, Performance API), but does not request file-write or unauthorized network operations.
  • Sanitization: Not applicable as the scope is limited to performance auditing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 05:58 PM
Security Audit — agent-trust-hub — first-contentful-paint