portal-router

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill functions as a portal to discover and load content from external Markdown files across multiple ecosystems into the agent's prompt context. This creates a surface for indirect prompt injection where malicious instructions embedded in a discovered skill could influence agent behavior.
  • Ingestion points: The references/resolve.py script reads the full text of .md files found in ~/_arms/mirror/ and ~/_arms/skills/ during the execution of the show command.
  • Boundary markers: The cmd_show function in references/resolve.py adds descriptive headers including ecosystem, type, name, and invoke path to the output, but does not provide specific delimiters or instructions to the agent to treat the subsequent file body as untrusted or non-executable data.
  • Capability inventory: The script performs directory traversal using os.walk with followlinks=True, follows symlinks, and reads file contents using Path.read_text to write them to standard output.
  • Sanitization: No sanitization, filtering, or instruction-stripping is performed on the content of the Markdown files before they are presented to the agent.
  • [COMMAND_EXECUTION]: The skill provides a Python-based engine that allows the agent to interact with the local filesystem to search, index, and display file contents. The cmd_show function allows the agent to output the contents of any file identified as a capability unit during the indexing phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — portal-router