Back to plugin

Security audit

Portage

Security checks for vulnerabilities and agentic risk

Overview

This plugin coherently exposes Portage shopping tools, including optional purchase and browser-import capabilities, with clear user approval and scoping instructions.

Install only if you intend to let an agent use Portage for shopping. Review optional tools before enabling them, especially buying, handoff, index mutation, and browser import. Keep payment enrollment, spending policy changes, credentials, and setup in your own terminal as the skill directs.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.