APort Agent Guardrail
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill's stated purpose is a security guardrail, which is benign. However, the `SKILL.md` instructs the AI agent to install software via `npx @aporthq/agent-guardrails` or by cloning a GitHub repository (`github.com/aporthq/aport-agent-guardrails`). These methods involve executing external code from npm or GitHub, introducing a supply chain vulnerability. While common for software installation, this constitutes a 'meaningful high-risk behavior' due to the reliance on unanalyzed external sources, classifying it as suspicious rather than benign. There is no evidence of intentional malicious behavior within the provided files themselves.
