portfolio-status

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were detected in the skill instructions.\n- [DATA_EXFILTRATION]: The skill reads from local data files (_log.yaml and CLAUDE.md) specifically located within a plugin configuration directory (~/.claude/plugins/config/). It does not contain any network-facing tools (e.g., curl, wget) or instructions to transmit this data externally.\n- [PROMPT_INJECTION]: The instructions are focused on data summarization and reporting. There are no attempts to override system prompts, bypass safety filters, or use adversarial role-play techniques.\n- [REMOTE_CODE_EXECUTION]: The skill does not download external scripts, install packages, or use dynamic execution functions (e.g., eval, exec).\n- [COMMAND_EXECUTION]: No shell commands or system-level operations are invoked. The workflow is restricted to reading and formatting structured data.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 07:07 AM
Security Audit — agent-trust-hub — portfolio-status