api-sports
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the global installation of the Membrane CLI tool (
@membranehq/cli) via npm to interact with the platform. This is a verified vendor resource from the skill author. - [COMMAND_EXECUTION]: The skill uses shell commands to manage agent authentication (
membrane login), established connections (membrane connection ensure), and execute sports-related actions. These are standard operations for a CLI-integrated skill. - [INDIRECT_PROMPT_INJECTION]: The skill processes real-time sports data and statistics from an external source (
api-sports.io), which represents a potential surface for indirect instructions. - Ingestion points: Data is ingested through action results (
membrane action run) and direct proxy requests (membrane request) in SKILL.md. - Boundary markers: There are no specific instructions for the agent to ignore potential instructions embedded within the sports data.
- Capability inventory: The skill possesses the ability to perform network requests through the Membrane proxy and execute CLI commands.
- Sanitization: Sanitization of the external API response is not explicitly detailed in the skill instructions.
Audit Metadata