portaly-overview

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches API metadata (llms.txt) and OpenAPI specifications (openapi.json) from the vendor's official domain at https://portaly.ai. These resources are used to provide the user with up-to-date API information.
  • [COMMAND_EXECUTION]: Provides instructions to install related skills using the npx skills add command (e.g., npx skills add portaly-ai/portaly-skills --skill portaly-payment). These commands target the vendor's official skill repository.
  • [DATA_EXFILTRATION]: Performs a conditional network request to https://portaly.ai/api/creator-subscription/skill-version to report the currently installed skill name and version. This operation requires the PORTALY_API_KEY to be present in the environment and is intended to enable version tracking in the merchant's dashboard. The transmitted data is limited to the skill's identification and version number.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:39 AM
Security Audit — agent-trust-hub — portaly-overview