appsmith

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the installation and use of the @membranehq/cli package from NPM. This is a standard utility provided by the skill's vendor (Membrane) to facilitate platform interactions and is considered a safe vendor resource.
  • [COMMAND_EXECUTION]: The skill instructs the agent to use various membrane CLI commands to authenticate, manage connections, and execute actions on the Appsmith platform. This is the primary intended functionality of the skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an interface for processing data from the Appsmith API, which represents a potential surface for indirect prompt injection.
  • Ingestion points: External data enters the agent's context through membrane action list, membrane action run, and proxy requests via membrane request as described in SKILL.md.
  • Boundary markers: The instructions do not explicitly define delimiters or markers to isolate API output from agent instructions.
  • Capability inventory: The skill has the ability to write to the external Appsmith platform through action execution and proxy requests as described in SKILL.md.
  • Sanitization: No explicit sanitization or filtering of API responses is detailed in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 04:30 AM
Security Audit — agent-trust-hub — appsmith