chrome-devtools-debug-optimize-lcp

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's provenance documentation identifies its source as the official ChromeDevTools repository on GitHub, which is a well-known service associated with a trusted organization.
  • [COMMAND_EXECUTION]: The SKILL.md file contains a developer-focused 'Validation Contract' that mentions using the 'uv' tool for auditing and packaging the skill. These commands are documentation for the developer's build process and are not instructions for the agent to execute during runtime.
  • [PROMPT_INJECTION]: The skill interacts with external website content to conduct performance audits. It utilizes specific JavaScript snippets to extract technical metadata (e.g., tag names, resource URLs, and timing data), which reduces the surface area for indirect prompt injection compared to processing unstructured text.
  • [SAFE]: No obfuscation, unauthorized persistence mechanisms, or credential exposure were detected. The skill includes explicit instructions for the agent to respect existing privacy and telemetry settings.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 06:12 PM
Security Audit — agent-trust-hub — chrome-devtools-debug-optimize-lcp