portal-router
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill functions as a portal to discover and load content from external Markdown files across multiple ecosystems into the agent's prompt context. This creates a surface for indirect prompt injection where malicious instructions embedded in a discovered skill could influence agent behavior.
- Ingestion points: The
references/resolve.pyscript reads the full text of.mdfiles found in~/_arms/mirror/and~/_arms/skills/during the execution of theshowcommand. - Boundary markers: The
cmd_showfunction inreferences/resolve.pyadds descriptive headers including ecosystem, type, name, and invoke path to the output, but does not provide specific delimiters or instructions to the agent to treat the subsequent file body as untrusted or non-executable data. - Capability inventory: The script performs directory traversal using
os.walkwithfollowlinks=True, follows symlinks, and reads file contents usingPath.read_textto write them to standard output. - Sanitization: No sanitization, filtering, or instruction-stripping is performed on the content of the Markdown files before they are presented to the agent.
- [COMMAND_EXECUTION]: The skill provides a Python-based engine that allows the agent to interact with the local filesystem to search, index, and display file contents. The
cmd_showfunction allows the agent to output the contents of any file identified as a capability unit during the indexing phase.
Audit Metadata