senpi-portfolio

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/portfolio.py utilizes the subprocess.run function to invoke the openclaw CLI for retrieving strategy registry and runtime health status. These operations are scoped to the platform's internal management tools.
  • [EXTERNAL_DOWNLOADS]: The engine performs network requests to raw.githubusercontent.com/Senpi-ai/ to download a strategy catalog and to mcp.prod.senpi.ai for data retrieval via the Model Context Protocol. These are official vendor endpoints used for standard skill functionality.
  • [PROMPT_INJECTION]: The skill instructions include stylistic guidelines such as "Pull the data quietly" to ensure a professional interaction tone. These instructions do not constitute a malicious override of the AI's safety protocols or an attempt to hide security-relevant actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 10:31 PM
Security Audit — agent-trust-hub — senpi-portfolio