acf

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches and installs the official Membrane CLI (@membranehq/cli) from the public npm registry to facilitate integration with the ACF API.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the membrane CLI for managing service connections, discovering available actions, and performing API requests.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external ACF API endpoints and actions which could potentially contain malicious instructions.
  • Ingestion points: Data is received into the agent's context via the output of membrane action run and membrane request commands in SKILL.md.
  • Boundary markers: The skill does not provide explicit instructions or delimiters to the agent to distinguish between its own logic and data returned from external sources.
  • Capability inventory: The agent possesses the capability to execute further shell commands, network requests, and connection management tasks based on instructions it may encounter in the data.
  • Sanitization: There is no documented sanitization, validation, or filtering of the content returned by the ACF API before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 04:56 AM
Security Audit — agent-trust-hub — acf