assembla

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli package from the NPM registry to interact with the Membrane platform.
  • [COMMAND_EXECUTION]: The skill relies on the membrane CLI tool for project operations. This includes the membrane action create command, which enables the dynamic generation of new actions and capabilities based on natural language descriptions provided at runtime.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface (Category 8) through the ingestion of external Assembla data.
  • Ingestion points: Data from tickets, comments, and merge requests is introduced into the agent context via actions listed in SKILL.md (e.g., list-tickets, get-ticket-comments).
  • Boundary markers: There are no boundary markers or instructions to isolate retrieved external data from the agent's instructions.
  • Capability inventory: The agent can perform significant operations such as create-ticket, update-ticket, and creating new actions via membrane action run (defined in SKILL.md).
  • Sanitization: The skill does not define any sanitization or validation logic for content fetched from the external service.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 06:50 PM
Security Audit — agent-trust-hub — assembla