Wraps ghz, the gRPC load testing tool, for throughput and latency benchmarking. Covers test invocation (--proto + --call + host:port; or --protoset for compiled descriptors), load parameters (-n total requests, -c concurrency, -r RPS rate limit, -z duration), output formats (json/csv/html/influx-summary for CI consumption), the metrics reported (RPS achieved, latency p50/p95/p99, status-code distribution, errors), and CI integration patterns for regression gating. Use when benchmarking a gRPC service's throughput or detecting latency regressions in CI.
69
87%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Medium
Suggest reviewing before use
Security
1 medium severity finding. This skill can be installed but you should review these findings before use.
The skill prompts the agent to compromise the security or integrity of the user’s machine by modifying system-level services or configurations, such as obtaining elevated privileges, altering startup scripts, or changing system-wide settings.
The CI installation step explicitly runs "sudo mv ghz /usr/local/bin/", which requests elevated privileges and modifies a system directory (changing the machine state), so this skill includes instructions that affect system-level files.
Low
Low-risk findings.
1 low severity finding. Worth noting, but not necessarily harmful.
The skill fetches instructions or code from an external URL at runtime, and the fetched content directly controls the agent’s prompts or executes code. This dynamic dependency allows the external source to modify the agent’s behavior without any changes to the skill itself.
The GitHub release URL https://github.com/bojand/ghz/releases/download/v0.120.0/ghz-linux-x86_64.tar.gz is fetched and extracted in the CI run step (curl ... | tar xz), which downloads and installs a binary at runtime—i.e., it fetches and enables execution of remote code required by the skill.
https://github.com/bojand/ghz/releases/download/v0.120.0/ghz-linux-x86_64.tar.gz
dependency · 1 site
The CI workflow fetches a remote tarball via curl and pipes it directly to tar for extraction, downloading and enabling execution of an unverified binary at runtime.
SKILL.md
218
curl -L https://github.com/bojand/ghz/releases/download/v0.120.0/ghz-linux-x86_64.tar.gz | tar xz
actions/checkout@v5
dependency · 1 site
The CI workflow invokes a hosted GitHub Action (actions/checkout@v5) as a runtime dependency.
SKILL.md
215
- uses: actions/checkout@v5
actions/cache@v4
dependency · 1 site
The CI workflow invokes a hosted GitHub Action (actions/cache@v4) as a runtime dependency.
SKILL.md
224
uses: actions/cache@v4
sudo mv ghz /usr/local/bin/
command · 1 site
The CI step installs the remotely-fetched ghz binary into a system directory with elevated privileges, completing the runtime installation of the unverified external dependency.
SKILL.md
219
sudo mv ghz /usr/local/bin/