next-bundle-optimizer

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • Sandbox Isolation Bypass: The skill contains explicit instructions to perform operations outside of the agent's restricted sandbox environment if certain technical limitations are encountered. This pattern is a security consideration as it guides the agent to circumvent platform-level execution boundaries.
  • Indirect Prompt Injection Surface: The skill is designed to ingest and interpret project source code and generated build artifacts (JSONL files). This creates an attack surface where instructions embedded in the analyzed project data could potentially influence the agent's logic. Ingestion points: Project source code (Step 4) and baseline analysis files (Step 3 in SKILL.md). Boundary markers: No explicit delimiters or instructions to ignore embedded content are present. Capability inventory: The skill utilizes shell execution, package manager commands (pnpm), and Node.js script execution. Sanitization: There is no evidence of sanitization or filtering for the external content processed.
  • Command Execution Interface: The skill relies heavily on shell commands and package manager execution to capture baselines and interpret graph evidence. While these are standard development practices, the use of executable commands provides a broad capability set that requires monitoring.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 04:06 PM