performance-pass-ui
Pass
Audited by Gen Agent Trust Hub on Jul 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were identified during analysis. The skill lacks obfuscation, network operations, or credential access.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted source code and repository metadata to perform performance analysis. While this presents an inherent attack surface for indirect prompt injection, it is required for the skill's primary function of code optimization.
- Ingestion points: Component source files and
REPO_PROFILE.jsonspecified in inputs. - Boundary markers: No explicit delimiters or instruction-guarding markers are provided for ingested content.
- Capability inventory: The skill has file-write permissions (
mode: write) to apply code changes. - Sanitization: No sanitization or validation of the input source code is explicitly performed.
Audit Metadata