auth0

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the official Membrane CLI tool (@membranehq/cli) from the npm registry. This is a standard installation of a vendor-provided tool for the platform.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a vulnerability surface as it ingests data from the Auth0 API (actions, logs, user records) and presents it to the agent. This is a standard characteristic of API-based skills.
  • Ingestion points: Data enters the context through membrane action list and membrane action run commands (SKILL.md).
  • Boundary markers: None identified in the prompt templates.
  • Capability inventory: The skill utilizes the membrane CLI to perform network operations and interact with the Auth0 management API (SKILL.md).
  • Sanitization: Not explicitly defined in the instruction set.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:07 PM
Security Audit — agent-trust-hub — auth0