portal-backend-app
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill references standard development and deployment commands (e.g., bun run dev:all, docker-compose) and configuration for the Caddy web server. These instructions are consistent with the monorepo's operational requirements and are for documentation purposes.
- [DATA_EXPOSURE_AND_EXFILTRATION]: Contains references to internal service endpoints and development-specific user accounts (e.g., rockie, liming, chenjing). These are identified as part of the vendor's (xgent-ai) testing and development infrastructure and do not include sensitive credentials.
- [INDIRECT_PROMPT_INJECTION]: The skill describes a framework for handling external authentication tokens (TDT). It explicitly prescribes security best practices to mitigate injection risks, including mandatory server-side token introspection and the enforcement of tenant isolation by relying on verified claims rather than request body data.
Audit Metadata