system-profile

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a wide array of system profiling and monitoring tools including perf stat, strace, iostat, vmstat, nvidia-smi, and nsys based on user-provided arguments.
  • [DYNAMIC_EXECUTION]: The instructions explicitly direct the agent to write instrumentation code (e.g., decorators, context managers, or inline edits) and insert it into existing target files to measure performance metrics. While the skill includes a mandatory changelog and cleanup process, modifying and executing modified code is a high-privilege activity.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection as it ingests and processes untrusted data from the user ($ARGUMENTS) and external files (target source code).
  • Ingestion points: The agent parses $ARGUMENTS to determine the target and reads the contents of files identified as profiling targets (e.g., Python scripts).
  • Boundary markers: There are no explicit instructions or delimiters provided to the agent to ignore or isolate potential natural language instructions embedded within the code being instrumented.
  • Capability inventory: The skill has the capability to write to the file system (Step 4) and execute arbitrary shell commands for profiling (Step 2/5).
  • Sanitization: The instructions do not specify any validation or sanitization of the content found within target files before the agent processes or instruments them.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:07 PM
Security Audit — agent-trust-hub — system-profile