developer-portfolio

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads a project template from a third-party GitHub repository.
  • Evidence: git clone --depth 1 https://github.com/Eng0AI/developer-portfolio-template.git . in SKILL.md.
  • [REMOTE_CODE_EXECUTION]: The skill executes code from the downloaded repository using package manager commands.
  • Evidence: pnpm install, pnpm build, and pnpm dev commands in SKILL.md execute scripts defined in the external repository.
  • [COMMAND_EXECUTION]: The skill uses shell commands to manipulate files and deploy the application.
  • Evidence: mv _temp_template/* _temp_template/.* ., rm -rf .git, vercel deploy, and netlify deploy.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by downloading untrusted content into the agent's working environment.
  • Ingestion points: Cloned repository files from https://github.com/Eng0AI/developer-portfolio-template.git.
  • Boundary markers: Absent.
  • Capability inventory: Shell command execution (pnpm, vercel, netlify), file system modification.
  • Sanitization: Absent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 05:35 AM