performance-engineer

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This skill is a professional performance-engineering guide with code examples for profiling, caching, load testing, query optimization, bundle budgets, and memory monitoring. I found no indications of credential harvesting, obfuscated malware, remote-download-and-execute chains, or exfiltration to suspicious endpoints. The primary operational risks are (1) unbounded disk writes from profiling/heap snapshots saved to /tmp, (2) potentially destructive cache invalidation if pattern inputs are misused, and (3) the normal risk of running load tests against production systems using real AUTH_TOKENs. Those are practical/operational concerns rather than evidence of malicious intent. Overall the artifact appears benign for its stated purpose but contains a few operational patterns that require careful, privileged, and rate-limited use.

Confidence: 75%Severity: 50%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:34 PM
Package URL
pkg:socket/skills-sh/jgarrison929%2Fopenclaw-skills%2Fperformance-engineer%2F@96956afdb0974c0a95ce210a407464373805c549