portless
Pass
Audited by Gen Agent Trust Hub on Apr 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
portless runcommand to start development servers and requiressudofor privileged operations like binding to port 80 or 443 and updating system trust stores as described inreferences/upstream.md. - [EXTERNAL_DOWNLOADS]: The skill directs users to install the
portlessCLI and references configuration and documentation synchronized from thevercel-labsorganization. - [PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection by allowing agents to interact with local servers via the
$PORTLESS_URL. Ingestion point: agent-browser opens the assigned URL inSKILL.md. Boundary markers: none identified in the instructions. Capability inventory: execution of local development commands. Sanitization: no validation or filtering of local server content is implemented.
Audit Metadata