acf
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches and installs the official Membrane CLI (
@membranehq/cli) from the public npm registry to facilitate integration with the ACF API. - [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the
membraneCLI for managing service connections, discovering available actions, and performing API requests. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external ACF API endpoints and actions which could potentially contain malicious instructions.
- Ingestion points: Data is received into the agent's context via the output of
membrane action runandmembrane requestcommands inSKILL.md. - Boundary markers: The skill does not provide explicit instructions or delimiters to the agent to distinguish between its own logic and data returned from external sources.
- Capability inventory: The agent possesses the capability to execute further shell commands, network requests, and connection management tasks based on instructions it may encounter in the data.
- Sanitization: There is no documented sanitization, validation, or filtering of the content returned by the ACF API before it is processed by the agent.
Audit Metadata