akamai

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package globally via npm. This is a vendor-provided utility tool used to facilitate communication between the agent and the Membrane platform.
  • [COMMAND_EXECUTION]: The instructions involve executing various shell commands using the membrane CLI tool to manage authentication states, establish service connections, and execute API actions against Akamai.
  • [INDIRECT_PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection through its data handling mechanisms.
  • Ingestion points: The skill ingests untrusted data from the Akamai API through membrane action run and search results from membrane action list. It also processes user-provided natural language 'intents'.
  • Boundary markers: The documentation does not prescribe the use of specific delimiters or instructions to ignore embedded commands within the processed data.
  • Capability inventory: The agent can perform shell command execution and network operations (via the proxy command) based on the data received.
  • Sanitization: No explicit sanitization or validation logic is defined for data returned from the Akamai API endpoints before it is consumed by the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:30 AM
Security Audit — agent-trust-hub — akamai