port-daddy
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates local command execution through background fleet agents and "watchers" defined in
pd-fleet.yml. These watchers can run arbitrary shell commands (exec) in response to pub/sub events. - Evidence:
schemas/pd-fleet.schema.jsondefineswatcher.execandagent.prompt.SKILL.mddescribespd spawnandpd fleet upcommands. - [PERSISTENCE]: The skill implements persistence by installing the daemon as a system service (e.g., macOS
launchd) and using git hooks to trigger agent activity. - Evidence:
SKILL.mdmentionspd installfor launchd services.examples/04-fleet-from-zero.mddescribes the creation of a.git/hooks/post-commithook. - [INDIRECT_PROMPT_INJECTION]: The skill creates a multi-agent environment where agents ingest data from shared state primitives (tuples, notes, inbox messages). This constitutes an indirect prompt injection surface typical of multi-agent coordination systems.
- Ingestion points: The daemon's shared tuple space, session notes, and agent inboxes (
schemas/tuple-shape.md,schemas/note-shape.md). - Boundary markers: Not explicitly defined in the shared state primitives or command templates.
- Capability inventory: Fleet agents can execute code via platform-defined
allowedTools(e.g.,Bash), and watchers can run shell commands. - Sanitization: Responsibility is delegated to the platform and sub-agent backends; coordination scripts do not implement additional filtering.
- [CREDENTIALS_UNSAFE]: The skill manages a local master encryption key and supports notification webhooks. While templates and paths are provided, no hardcoded secrets are present.
- Evidence:
SKILL.mddefines the location for~/.port-daddy/master.key.assets/.portdaddyrc.starterincludes a placeholder for aninconsistency_webhook. - [EXTERNAL_DOWNLOADS]: Documentation files reference well-known external resources for rendering architecture diagrams.
- Evidence:
architecture.htmlfetches the Mermaid.js library from thecdn.jsdelivr.netCDN.
Audit Metadata