product-performance-engineering
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references technical documentation and performance guidelines from trusted organizations such as Google (Android, Web Vitals), Apple (MetricKit, Instruments), and Meta (React Native). These are used to provide authoritative technical context for performance tasks.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies performance artifacts (traces, logs, heap dumps) as potential ingestion points for untrusted data. It provides mitigations by instructing the agent to treat these as evidence rather than instructions, redact sensitive data locally, and avoid executing any commands found within these files.
- Ingestion points: Performance traces, heap dumps, logs, and telemetry data processed during diagnosis in references/experience-and-integrity-boundaries.md.
- Boundary markers: Explicit instructions in SKILL.md to treat artifacts as evidence rather than instructions and use delimiters for untrusted data.
- Capability inventory: Benchmarking and profiling tools, with code generation limited to authorized optimization patches.
- Sanitization: Explicit requirement in references/field-observability.md and references/experience-and-integrity-boundaries.md to redact or aggregate sensitive content locally.
Audit Metadata