api-sports

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the global installation of the Membrane CLI tool (@membranehq/cli) via npm to interact with the platform. This is a verified vendor resource from the skill author.
  • [COMMAND_EXECUTION]: The skill uses shell commands to manage agent authentication (membrane login), established connections (membrane connection ensure), and execute sports-related actions. These are standard operations for a CLI-integrated skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes real-time sports data and statistics from an external source (api-sports.io), which represents a potential surface for indirect instructions.
  • Ingestion points: Data is ingested through action results (membrane action run) and direct proxy requests (membrane request) in SKILL.md.
  • Boundary markers: There are no specific instructions for the agent to ignore potential instructions embedded within the sports data.
  • Capability inventory: The skill possesses the ability to perform network requests through the Membrane proxy and execute CLI commands.
  • Sanitization: Sanitization of the external API response is not explicitly detailed in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:13 AM
Security Audit — agent-trust-hub — api-sports