portfolio-story-architecture

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill directs the agent to access external URLs to inspect media for design references.
  • Evidence: Multiple links in references/cases.md pointing to goodcase.ai, twimg.com, and x.com.
  • Context: These network operations are intended for visual style verification.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests 'Case evidence' including prompt excerpts and external media content.
  • Ingestion points: The references/cases.md file contains prompt snippets and external links.
  • Boundary markers: A 'Safety and attribution' section and a 'reference contract' workflow are defined in SKILL.md.
  • Capability inventory: The agent is instructed to use browser, image, or video tools.
  • Sanitization: No explicit filtering or sanitization of external media content is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 06:37 AM
Security Audit — agent-trust-hub — portfolio-story-architecture