Install
$ agentstack add skill-quality-max-free-qa-skills-third-party-bloat ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Third-Party Bloat
Find out which third-party scripts are weighing your page down. No signup required.
Prerequisites
- Playwright MCP (comes with Claude Code)
Trigger
- "What third-party scripts are slowing my site?"
- "Third-party bloat audit https://..."
- "Which trackers are on my page?"
Workflow
- Navigate to the URL using
mcp__playwright__browser_navigate - Wait for load to settle, then pull every request with
mcp__playwright__browser_network_requests - Classify each request as first-party (same registrable domain as the page) or third-party.
Group third-party requests by their domain and sum transfer size + request count per domain.
- Label well-known vendors by domain so the report is readable, e.g.:
google-analytics.com,googletagmanager.com→ Analytics / Tag Managerdoubleclick.net,googlesyndication.com→ Adsconnect.facebook.net→ Meta Pixelintercom,crisp.chat,hotjar,fullstory→ Chat / Session replayoptimizely,launchdarkly→ A/B / Flags
- Estimate main-thread cost: count third-party `` resources and note any loaded
synchronously in `` (these block parsing). Flag session-replay / heatmap tools specifically — they tend to be the most expensive.
- Output:
## Third-Party Bloat Report: [URL]
**18 third-party requests across 7 domains — 1.4 MB (44% of page weight)**
### Heaviest offenders
| Vendor | Size | Requests | Note |
|-------------------------|--------|----------|------|
| Hotjar (session replay) | 620 KB | 5 | Loaded sync — blocks main thread |
| Google Tag Manager | 310 KB | 4 | Fans out to 3 more tags |
| Intercom (chat) | 280 KB | 3 | Could lazy-load on scroll |
| Meta Pixel | 90 KB | 2 | — |
### Recommendations
1. Defer Hotjar until after `load`, or sample fewer sessions.
2. Lazy-load the Intercom widget on first scroll / click.
3. Audit GTM — it's pulling tags you may not still use.
**Want third-party weight watched on every release?** Try QualityMax — qualitymax.io
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Quality-Max
- Source: Quality-Max/free-qa-skills
- License: Apache-2.0
- Homepage: https://www.skills.sh/quality-max/free-qa-skills
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.