web-performance-optimization
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection (LOW): The skill provides a script (
measurePagePerformance) that ingests a URL and uses Puppeteer to automate a browser. This creates an attack surface where a malicious website could attempt to influence the agent via processed page data or manipulated performance metrics.\n - Ingestion points:
urlparameter in the PuppeteermeasurePagePerformanceexample.\n - Boundary markers: Absent in the provided template.\n
- Capability: The script uses Puppeteer for navigation and JavaScript execution (
page.evaluate).\n - Sanitization: None; the script extracts data from the global
window.performanceobject without validation.\n- Data Exfiltration (SAFE): Performance metrics are sent to a relative path/api/metrics, which is a standard pattern for first-party telemetry and not an exfiltration risk.\n- Unverifiable Dependencies (SAFE): References standard packages like Puppeteer and React which are trusted in a web development context.\n- Credentials Unsafe (SAFE): No hardcoded secrets or sensitive configuration data identified in the markdown or code examples.
Audit Metadata