rspack-perf-valgrind-goal
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a bash script
scripts/run_local_valgrind.shto coordinate a measurement loop involvingdocker build,docker run, andpnpm run. Inside the containerized environment, it performs runtime compilation of Rust code usingcargo buildand executes the resulting binaries throughvalgrindwith thecallgrindtool. - [PRIVILEGE_ESCALATION]: The Docker execution environment is configured with
--cap-add SYS_PTRACEand--security-opt seccomp=unconfined. These settings grant the containerized process the ability to monitor and intercept system calls of other processes and bypass standard security profiles. While necessary for Valgrind's instrumentation to work, this represents a reduction in the security isolation between the container and the host system. - [PRIVILEGE_ESCALATION]: Upon completion of the measurement, the script executes
chmod -R a+rwXon the/resultsdirectory inside the container. Because this directory is a volume mount from the host, it changes the permissions of the local output files to be world-readable, world-writable, and executable. - [INDIRECT_PROMPT_INJECTION]: The skill contains a vulnerability surface where it ingests untrusted data such as user-supplied benchmark filters and benchmark output logs.
- Ingestion points: User-provided
bench_filterparameter; stdout/stderr logs from benchmark binaries; Callgrind profile files. - Boundary markers: None explicitly implemented to separate instructions from processed data.
- Capability inventory: Local shell execution via
bash; Docker container management; Git operations (commit/push); file system writes. - Sanitization: The
run_local_valgrind.shscript performs basic validation on thebench_targetandrepeat_countparameters, but does not sanitize the benchmark filter or the contents of logs used for reporting.
Audit Metadata