Back to skill

Security audit

Performance Optimization

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent frontend performance-analysis skill with disclosed report-writing behavior and no evidence of hidden execution, credential access, exfiltration, or persistence beyond saving a local report.

Install this if you want agents to follow an evidence-based frontend performance review workflow. Be aware it may read relevant project files and monitoring/build outputs, rerun project performance or validation commands, and write a local report file under reports/.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

md
- ID: `fec-performance-optimization`
- Category: `review-quality`
- Version: `2.9.0`
- Source: `skills/fec-performance-optimization/SKILL.md`

## Description

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README says to use the skill when diagnosing or improving frontend performance and lists triggers such as 'performance optimization' and 'page freeze'. These phrases are broad and common in general troubleshooting contexts, and the file does not provide explicit boundaries, negative examples, or activation constraints to prevent unintended invocation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation description contains broad trigger terms such as 'performance optimization', 'slow first screen', and 'Web Vitals' that can match many normal frontend requests and cause the skill to activate when a more specific skill would be more appropriate. This is not directly code-execution dangerous, but it can expand the skill's scope, increase unintended invocation frequency, and lead to misleading or irrelevant guidance being applied to unrelated tasks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This manifest file's description says to use the skill when diagnosing or improving frontend performance and includes trigger phrases like 'performance optimization' and 'page freeze'. These terms are broad enough to overlap with many ordinary engineering requests, and the manifest does not provide explicit negative examples or tighter activation boundaries to clarify when the skill should not be invoked.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The package description defines a very broad activation scope covering many common frontend concerns, which can cause the skill to be invoked in situations beyond narrowly scoped performance analysis. Over-broad triggers increase the chance that the agent applies this skill to unrelated tasks, potentially steering behavior unexpectedly or bypassing more appropriate, safer specialist skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The description explicitly specifies that Chinese triggers include a fixed set of phrases, but it does not say this is optional or user-selectable. This can be a locale-policy issue because it introduces a language-specific behavior without documenting user opt-in or broader language support.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The description explicitly states 'Chinese triggers include ...' but does not present language handling as optional or explain a locale-specific requirement. This can constitute a language/locale policy issue because it introduces a specific language constraint without clear user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The template includes a broad instruction to save a generated report to a repository path after analysis completes, without clear scoping, user confirmation, or constraints on when file-writing is appropriate. In an agentic environment, such unconditional persistence can trigger unintended filesystem writes, create unauthorized artifacts, or normalize write actions beyond the user's explicit request.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.