appsmith
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the installation and use of the
@membranehq/clipackage from NPM. This is a standard utility provided by the skill's vendor (Membrane) to facilitate platform interactions and is considered a safe vendor resource. - [COMMAND_EXECUTION]: The skill instructs the agent to use various
membraneCLI commands to authenticate, manage connections, and execute actions on the Appsmith platform. This is the primary intended functionality of the skill. - [INDIRECT_PROMPT_INJECTION]: The skill establishes an interface for processing data from the Appsmith API, which represents a potential surface for indirect prompt injection.
- Ingestion points: External data enters the agent's context through
membrane action list,membrane action run, and proxy requests viamembrane requestas described in SKILL.md. - Boundary markers: The instructions do not explicitly define delimiters or markers to isolate API output from agent instructions.
- Capability inventory: The skill has the ability to write to the external Appsmith platform through action execution and proxy requests as described in SKILL.md.
- Sanitization: No explicit sanitization or filtering of API responses is detailed in the skill instructions.
Audit Metadata