core-web-vitals-performance-contracts
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions consist of technical checklists and standard search patterns (
rg) used to audit codebase performance. No command injection vulnerabilities or dangerous shell commands were detected in the provided patterns. - [SAFE]: All external references target official and trusted developer documentation platforms, including web.dev and MDN (Mozilla Developer Network).
- [SAFE]: The skill does not request or use any sensitive permissions, perform network operations, or include hidden or obfuscated content.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process source code files, which constitutes a surface for indirect instructions. However, the skill is scoped to diagnostic analysis and does not possess high-risk capabilities—such as network exfiltration, credential access, or unauthorized file writes—rendering the injection surface non-exploitable.
Audit Metadata