portless

Pass

Audited by Gen Agent Trust Hub on Apr 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the portless run command to start development servers and requires sudo for privileged operations like binding to port 80 or 443 and updating system trust stores as described in references/upstream.md.
  • [EXTERNAL_DOWNLOADS]: The skill directs users to install the portless CLI and references configuration and documentation synchronized from the vercel-labs organization.
  • [PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection by allowing agents to interact with local servers via the $PORTLESS_URL. Ingestion point: agent-browser opens the assigned URL in SKILL.md. Boundary markers: none identified in the instructions. Capability inventory: execution of local development commands. Sanitization: no validation or filtering of local server content is implemented.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 8, 2026, 11:39 PM