software-performance

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill instructions and associated Python scripts do not contain malicious patterns, obfuscation, or unauthorized access to sensitive system resources. The overall design focuses on legitimate performance engineering tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes performance reports (JSON) via the scripts/check_perf_budget.py tool. Security analysis confirms that this script uses safe parsing methods (json.loads) and only extracts specific numeric metrics for comparison. The output is strictly formatted markdown containing metrics and thresholds, which mitigates any risk of downstream prompt injection from untrusted report data.
  • [EXTERNAL_DOWNLOADS]: The skill references several industry-standard performance tools and documentation sources, including Google's Web Vitals, k6, Lighthouse, and async-profiler. All external references are to official documentation or well-known, reputable services, posing no threat to the execution environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — software-performance