skills/tonone-ai/tonone/spine-perf/Gen Agent Trust Hub

spine-perf

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a bundled vendor script team/spine/scripts/spine_agent/perf_scan.py to perform static analysis on source files and profile web endpoints. This script is part of the skill's internal directory structure.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection. It ingests untrusted code from the user's project to identify performance issues and suggests or applies fixes using Write, Edit, and Bash tools.
  • Ingestion points: Reads project source files (Python, Go, JS, Ruby) and database schemas during analysis steps.
  • Boundary markers: None. The instructions do not specify any delimiters or warnings to ignore instructions embedded within the analyzed code.
  • Capability inventory: The skill has access to Read, Write, Edit, Bash, Glob, Grep, WebFetch, and WebSearch tools.
  • Sanitization: There is no evidence of sanitization or validation of the code content before it is processed or used to generate repair instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:48 PM
Security Audit — agent-trust-hub — spine-perf