senpi-portfolio
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/portfolio.pyutilizes thesubprocess.runfunction to invoke theopenclawCLI for retrieving strategy registry and runtime health status. These operations are scoped to the platform's internal management tools. - [EXTERNAL_DOWNLOADS]: The engine performs network requests to
raw.githubusercontent.com/Senpi-ai/to download a strategy catalog and tomcp.prod.senpi.aifor data retrieval via the Model Context Protocol. These are official vendor endpoints used for standard skill functionality. - [PROMPT_INJECTION]: The skill instructions include stylistic guidelines such as "Pull the data quietly" to ensure a professional interaction tone. These instructions do not constitute a malicious override of the AI's safety protocols or an attempt to hide security-relevant actions.
Audit Metadata