portals-config
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests portal configuration data from the
/portals-manager/api(as described inSKILL.mdandreferences/recipes.md). This content, which includes Markdown-formatted contact information and footer text, represents a potential indirect injection surface where malicious instructions could be embedded in data processed by the agent. - Ingestion points:
GET /portals/:id,GET /pages(mentioned inSKILL.mdandreferences/recipes.md). - Boundary markers: The instructions do not define specific delimiters or warnings to ignore instructions within the retrieved configuration data.
- Capability inventory: The skill utilizes network requests (
fetch) and script execution (evaluate_script) to modify portal states. - Sanitization: No explicit agent-side sanitization is described for the data fetched from the portal API.- [DYNAMIC_EXECUTION]: The skill provides JavaScript code templates in
references/recipes.mdfor the agent to execute using browser automation tools. This involves generating and running code at runtime to interact with the management interface, which is an expected part of the skill's operational flow but constitutes a dynamic execution pattern.
Audit Metadata