developer-portfolio
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads a project template from a third-party GitHub repository.
- Evidence:
git clone --depth 1 https://github.com/Eng0AI/developer-portfolio-template.git .inSKILL.md. - [REMOTE_CODE_EXECUTION]: The skill executes code from the downloaded repository using package manager commands.
- Evidence:
pnpm install,pnpm build, andpnpm devcommands inSKILL.mdexecute scripts defined in the external repository. - [COMMAND_EXECUTION]: The skill uses shell commands to manipulate files and deploy the application.
- Evidence:
mv _temp_template/* _temp_template/.* .,rm -rf .git,vercel deploy, andnetlify deploy. - [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by downloading untrusted content into the agent's working environment.
- Ingestion points: Cloned repository files from
https://github.com/Eng0AI/developer-portfolio-template.git. - Boundary markers: Absent.
- Capability inventory: Shell command execution (
pnpm,vercel,netlify), file system modification. - Sanitization: Absent.
Audit Metadata