web-perf
Pass
Audited by Gen Agent Trust Hub on Mar 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows best practices for web performance auditing and uses standard, well-documented MCP tools for browser interaction.- [EXTERNAL_DOWNLOADS]: The skill provides instructions for the user to install the 'chrome-devtools-mcp' package from the NPM registry, which is a well-known and standard service for this ecosystem.- [PROMPT_INJECTION]: There is a surface for indirect prompt injection because the skill navigates to external target URLs and processes their content. 1. Ingestion points:
navigate_page(SKILL.md) 2. Boundary markers: Absent 3. Capability inventory:navigate_page,list_network_requests,get_network_request,performance_start_trace,take_snapshot(SKILL.md) 4. Sanitization: Absent. This risk is inherent to any tool designed to browse and audit the live web.
Audit Metadata