Oathe Security Badge

Is infinyte/portfolio-showcase-generator safe?

https://github.com/infinyte/portfolio-showcase-generator

92
SAFE

The portfolio-showcase-generator skill is a legitimate documentation tool that helps engineers create professional portfolio materials from technical projects. While credential file access was detected during the session, this appears to be from system processes rather than the skill itself.

Category Scores

Prompt Injection 95/100 · 30%
Data Exfiltration 85/100 · 25%
Code Execution 95/100 · 20%
Clone Behavior 95/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 90/100 · 5%

Findings (1)

MEDIUM Credential File Access During Session -15

Multiple sensitive credential files were accessed during the audit session, including SSH keys, AWS credentials, and other authentication files. However, analysis indicates these accesses were from system authentication processes (sshd, sudo) rather than the skill itself.