portfolio

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is subject to indirect prompt injection risks due to its ability to process untrusted data from external sources.
  • Ingestion points: Data is ingested from the portfolio.yaml file, external spreadsheet uploads, and API integrations with third-party IP Management Systems (IPMS) such as Anaqua or Clarivate.
  • Boundary markers: The instructions do not provide explicit delimiters or instructions for the agent to ignore embedded commands within the processed data.
  • Capability inventory: The skill performs file read/write operations on its internal configuration and generates formatted reports; no direct system command execution or arbitrary code evaluation patterns were identified.
  • Sanitization: No input validation or sanitization routines are specified for handling external data.
  • [COMMAND_EXECUTION]: The skill uses a structured command-line interface with flags such as --report, --add, --update, and --audit to guide the agent through specific legal workflows.
  • [EXTERNAL_DOWNLOADS]: The skill supports fetching portfolio data from external, well-known IP management services through MCP connectors. These integrations are documented as legitimate functional requirements for the skill's operation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 03:59 PM
Security Audit — agent-trust-hub — portfolio