aftership
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@membranehq/clipackage from the NPM registry, which is the official tool provided by the skill's authoring organization. - [COMMAND_EXECUTION]: The skill requires the execution of the
membranecommand-line utility to handle login, connection management, and API requests to AfterShip. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The agent processes external shipment data and tracking information retrieved via AfterShip API actions in
SKILL.md. - Boundary markers: The skill does not define specific markers to delimit data from instructions when the agent processes API outputs.
- Capability inventory: The skill utilizes the
membraneCLI for network communication and data manipulation. - Sanitization: No explicit sanitization of the remote shipment data is mentioned in the prompt instructions.
Audit Metadata