portfolio-communicate

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to run validation scripts, resolving the plugin's root directory dynamically via shell commands (ls -td) targeting the user's plugin cache. This behavior is used to find internal tools like validate-entities.sh and project-status.sh.- [PROMPT_INJECTION]: Ingests and processes untrusted project data (JSON files) which are transformed into documentation by sub-agents, creating a surface for indirect prompt injection.
  • Ingestion points: Reads project-specific entities from products/, features/, propositions/, solutions/, packages/, competitors/, and customers/ directories.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the logic for handling these data inputs.
  • Capability inventory: The skill and its sub-agents have access to Bash for shell execution and Write for file system modifications.
  • Sanitization: Employs the communicate-review-assessor agent to perform multi-perspective quality evaluations and implements a closed-loop revision workflow to correct issues before finalization.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 01:51 PM
Security Audit — agent-trust-hub — portfolio-communicate