airbyte
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the Membrane CLI (
@membranehq/cli) via npm. This is a core requirement for interacting with the Membrane platform and is a vendor-provided resource. - [COMMAND_EXECUTION]: The skill utilizes shell commands to perform authentication, connection management, and data synchronization tasks. These commands include
membrane login,membrane connection ensure, andmembrane action run. All commands are scoped to the intended integration logic. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: Data ingested from external Airbyte sources and destinations via
membrane action runormembrane request(SKILL.md). - Boundary markers: The instructions do not specify explicit boundary markers or delimiters for untrusted data processed by the agent.
- Capability inventory: The skill uses shell command execution via the Membrane CLI to interact with external APIs.
- Sanitization: The skill advocates for using pre-built actions which provide managed mapping and error handling, reducing the surface for raw data injection compared to custom API implementations.
Audit Metadata