Security audit
Portage
Security checks for vulnerabilities and agentic risk
Overview
This plugin coherently exposes Portage shopping tools, including optional purchase and browser-import capabilities, with clear user approval and scoping instructions.
Install only if you intend to let an agent use Portage for shopping. Review optional tools before enabling them, especially buying, handoff, index mutation, and browser import. Keep payment enrollment, spending policy changes, credentials, and setup in your own terminal as the skill directs.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
