rspack-perf-codspeed-goal

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits a significant attack surface for indirect prompt injection because it is designed to ingest and act upon data from external, potentially untrusted sources such as GitHub PR comments and reviewer feedback.
  • Ingestion points: The agent reads "unresolved code review comments," "Copilot and human reviewer comments," and "CodSpeed PR comments" to drive its per-round iteration logic (Step 7 and 8 in SKILL.md).
  • Boundary markers: There are no explicit instructions to use delimiters or to treat these external comments as data rather than instructions. The agent is specifically told to "implement the fix" if a comment is "reasonable."
  • Capability inventory: The skill possesses high autonomy and powerful capabilities, including the ability to modify local source code, execute build scripts (JS and Rust), run system tests, and push commits to a GitHub repository.
  • Sanitization: There is no mention of filtering, sanitizing, or validating the content of these external comments before the agent incorporates them into its engineering decisions.
  • [COMMAND_EXECUTION]: The skill uses various shell commands and tools to fulfill its optimization loop, which are executed based on the agent's autonomous decisions.
  • The instructions specify using gh (GitHub CLI) for repository operations.
  • The loop involves executing language-specific build tools (JS/TS builds and Rust/Cargo builds), lints (clippy), and test suites.
  • While these are standard development tasks, the high degree of autonomy ("keep making the next best engineering decision without asking for routine confirmation") increases the impact if the agent is misled by injected instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:52 PM
Security Audit — agent-trust-hub — rspack-perf-codspeed-goal