core-web-vitals-performance-contracts

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions consist of technical checklists and standard search patterns (rg) used to audit codebase performance. No command injection vulnerabilities or dangerous shell commands were detected in the provided patterns.
  • [SAFE]: All external references target official and trusted developer documentation platforms, including web.dev and MDN (Mozilla Developer Network).
  • [SAFE]: The skill does not request or use any sensitive permissions, perform network operations, or include hidden or obfuscated content.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process source code files, which constitutes a surface for indirect instructions. However, the skill is scoped to diagnostic analysis and does not possess high-risk capabilities—such as network exfiltration, credential access, or unauthorized file writes—rendering the injection surface non-exploitable.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:59 PM
Security Audit — agent-trust-hub — core-web-vitals-performance-contracts