botpress
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the
@membranehq/clipackage globally via npm to enable communication with the Membrane platform. - [COMMAND_EXECUTION]: The skill provides numerous shell commands for the
membraneCLI to manage Botpress connections, search for actions, and execute API requests through a proxy feature. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to ingest and act upon data from external sources.
- Ingestion points: Untrusted chat messages, user profiles, and conversation metadata are retrieved from Botpress using tools like
list-messagesandget-user. - Boundary markers: There are no explicit delimiters or boundary markers defined in the instructions to help the agent isolate untrusted data.
- Capability inventory: The skill allows the agent to perform write operations (e.g.,
create-message) and execute arbitrary API requests viamembrane requestbased on its processing of the data. - Sanitization: No explicit logic or instructions are provided to sanitize external content before the agent processes it in its context.
Audit Metadata