port-daddy

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates local command execution through background fleet agents and "watchers" defined in pd-fleet.yml. These watchers can run arbitrary shell commands (exec) in response to pub/sub events.
  • Evidence: schemas/pd-fleet.schema.json defines watcher.exec and agent.prompt. SKILL.md describes pd spawn and pd fleet up commands.
  • [PERSISTENCE]: The skill implements persistence by installing the daemon as a system service (e.g., macOS launchd) and using git hooks to trigger agent activity.
  • Evidence: SKILL.md mentions pd install for launchd services. examples/04-fleet-from-zero.md describes the creation of a .git/hooks/post-commit hook.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a multi-agent environment where agents ingest data from shared state primitives (tuples, notes, inbox messages). This constitutes an indirect prompt injection surface typical of multi-agent coordination systems.
  • Ingestion points: The daemon's shared tuple space, session notes, and agent inboxes (schemas/tuple-shape.md, schemas/note-shape.md).
  • Boundary markers: Not explicitly defined in the shared state primitives or command templates.
  • Capability inventory: Fleet agents can execute code via platform-defined allowedTools (e.g., Bash), and watchers can run shell commands.
  • Sanitization: Responsibility is delegated to the platform and sub-agent backends; coordination scripts do not implement additional filtering.
  • [CREDENTIALS_UNSAFE]: The skill manages a local master encryption key and supports notification webhooks. While templates and paths are provided, no hardcoded secrets are present.
  • Evidence: SKILL.md defines the location for ~/.port-daddy/master.key. assets/.portdaddyrc.starter includes a placeholder for an inconsistency_webhook.
  • [EXTERNAL_DOWNLOADS]: Documentation files reference well-known external resources for rendering architecture diagrams.
  • Evidence: architecture.html fetches the Mermaid.js library from the cdn.jsdelivr.net CDN.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:13 AM
Security Audit — agent-trust-hub — port-daddy