spine-perf
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a bundled vendor script
team/spine/scripts/spine_agent/perf_scan.pyto perform static analysis on source files and profile web endpoints. This script is part of the skill's internal directory structure. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection. It ingests untrusted code from the user's project to identify performance issues and suggests or applies fixes using
Write,Edit, andBashtools. - Ingestion points: Reads project source files (Python, Go, JS, Ruby) and database schemas during analysis steps.
- Boundary markers: None. The instructions do not specify any delimiters or warnings to ignore instructions embedded within the analyzed code.
- Capability inventory: The skill has access to
Read,Write,Edit,Bash,Glob,Grep,WebFetch, andWebSearchtools. - Sanitization: There is no evidence of sanitization or validation of the code content before it is processed or used to generate repair instructions.
Audit Metadata