port-page
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is a legitimate development utility designed to facilitate structured code migration. It utilizes markdown templates for discovery and planning, ensuring that all operations are documented and transparent. No malicious patterns such as obfuscation, persistence mechanisms, or credential harvesting were detected.
- [PROMPT_INJECTION]: The skill contains an indirect prompt injection surface as it is designed to ingest and analyze external source code and content from user-provided paths and URLs. This risk is assessed as safe because the capability is necessary for the skill's primary function and is mitigated by a multi-step structured workflow. Ingestion points: Source page path or live URL provided in SKILL.md. Boundary markers: The skill mandates independent probing and the creation of a port plan in separate files before implementation. Capability inventory: The agent has the ability to write documentation and source files and execute platform-level commands like /responsive-pass. Sanitization: No explicit sanitization or filtering of external source content is described.
- [COMMAND_EXECUTION]: The skill invokes platform-specific commands such as /responsive-pass for visual verification. This is an expected part of the porting workflow and does not represent a security risk within the context of the agent's environment.
Audit Metadata