akamai
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@membranehq/clipackage globally via npm. This is a vendor-provided utility tool used to facilitate communication between the agent and the Membrane platform. - [COMMAND_EXECUTION]: The instructions involve executing various shell commands using the
membraneCLI tool to manage authentication states, establish service connections, and execute API actions against Akamai. - [INDIRECT_PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection through its data handling mechanisms.
- Ingestion points: The skill ingests untrusted data from the Akamai API through
membrane action runand search results frommembrane action list. It also processes user-provided natural language 'intents'. - Boundary markers: The documentation does not prescribe the use of specific delimiters or instructions to ignore embedded commands within the processed data.
- Capability inventory: The agent can perform shell command execution and network operations (via the proxy command) based on the data received.
- Sanitization: No explicit sanitization or validation logic is defined for data returned from the Akamai API endpoints before it is consumed by the agent's context.
Audit Metadata