anthropic

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation instructs users to install the @membranehq/cli package from the official npm registry. This package is the command-line interface for the Membrane platform, which is the service used to integrate the skill with Anthropic.\n- [COMMAND_EXECUTION]: The skill utilizes the membrane command-line tool to perform administrative and operational tasks, including logging into the platform, ensuring connections to the Anthropic domain, and executing specific API actions. These commands are essential to the documented workflow.\n- [INDIRECT_PROMPT_INJECTION]: The skill includes functionality to ingest and process data from the Anthropic API, which presents an attack surface for indirect prompt injection if the external data contains malicious instructions.\n
  • Ingestion points: Data retrieved from the Anthropic API via membrane action run and membrane request commands.\n
  • Boundary markers: The documented command examples do not specify the use of delimiters or instructions to ignore embedded content within the returned API data.\n
  • Capability inventory: The skill environment has the capability to execute shell commands using the membrane CLI tool.\n
  • Sanitization: There are no explicit instructions or mechanisms mentioned for sanitizing, validating, or filtering the data received from the external API before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:54 PM
Security Audit — agent-trust-hub — anthropic