portals-pages
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use browser-based JavaScript execution tools (such as
evaluate_scriptorbrowser_evaluate) to interact with the Portals Manager API and inspect the browser environment. - Evidence: The skill provides multiple JavaScript snippets in
references/api-workflow.mddesigned to be executed within a browser session to perform CRUD operations on portal pages. - [DYNAMIC_EXECUTION]: The skill uses dynamic script generation to construct API requests and handle browser-side logic at runtime.
- Evidence: JS snippets in
references/api-workflow.mddynamically construct JSON payloads and fetch requests using values likepageIdandownercontext retrieved from the session. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it ingests and processes portal configurations, external images from URLs, and HTML content from APIs.
- Ingestion points:
GET /portals-manager/api/pages/:idandfetch(url)for image uploads inreferences/api-workflow.md. - Boundary markers: The skill mentions that elements like text and alerts use "markdown sanitisé" to mitigate risks from embedded HTML or scripts.
- Capability inventory: The skill has high-privilege capabilities including browser script execution, network fetch requests, and state modification via API.
- Sanitization: Markdown sanitization is explicitly mentioned for content rendering in the portal manager.
- [EXTERNAL_DOWNLOADS]: The documentation references a well-known Node.js package for rendering diagrams when the built-in block is unavailable.
- Evidence:
references/mermaid.mdsuggests usingnpx -y @mermaid-js/mermaid-clito render diagrams as a fallback mechanism. - [CREDENTIALS_UNSAFE]: The skill includes instructions to read and decode JWT session tokens from browser cookies to verify user roles.
- Evidence:
references/api-workflow.mdprovides code to extractid_tokenfromdocument.cookieand decode the payload usingatob. This is used solely for local permission checks (e.g., verifyingadminvscontribroles) within the same-origin manager context.
Audit Metadata