clerk-orgs
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential surface for indirect prompt injection through the processing of untrusted external data within administrative workflows.\n
- Ingestion points: Data enters the agent's context through user-provided parameters such as email addresses, roles, and organization metadata in
references/invitations.md(e.g.,inviteMemberfunction) andSKILL.md(e.g.,clerk apiCLI commands).\n - Boundary markers: There are no explicit delimiters or specific instructions provided to the agent to treat interpolated variables as untrusted or to ignore embedded instructions within these data fields.\n
- Capability inventory: The skill facilitates administrative actions including organization creation, membership modification, and invitation management using both the
clerkCLI and the Clerk Backend API (clerkClient) across all reference files.\n - Sanitization: The provided code snippets and instructions do not include explicit sanitization, validation, or escaping logic for user-supplied strings before they are utilized in backend API requests or CLI command arguments.
Audit Metadata