aftership

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package from the NPM registry, which is the official tool provided by the skill's authoring organization.
  • [COMMAND_EXECUTION]: The skill requires the execution of the membrane command-line utility to handle login, connection management, and API requests to AfterShip.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The agent processes external shipment data and tracking information retrieved via AfterShip API actions in SKILL.md.
  • Boundary markers: The skill does not define specific markers to delimit data from instructions when the agent processes API outputs.
  • Capability inventory: The skill utilizes the membrane CLI for network communication and data manipulation.
  • Sanitization: No explicit sanitization of the remote shipment data is mentioned in the prompt instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:36 AM
Security Audit — agent-trust-hub — aftership