botpress

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the @membranehq/cli package globally via npm to enable communication with the Membrane platform.
  • [COMMAND_EXECUTION]: The skill provides numerous shell commands for the membrane CLI to manage Botpress connections, search for actions, and execute API requests through a proxy feature.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to ingest and act upon data from external sources.
  • Ingestion points: Untrusted chat messages, user profiles, and conversation metadata are retrieved from Botpress using tools like list-messages and get-user.
  • Boundary markers: There are no explicit delimiters or boundary markers defined in the instructions to help the agent isolate untrusted data.
  • Capability inventory: The skill allows the agent to perform write operations (e.g., create-message) and execute arbitrary API requests via membrane request based on its processing of the data.
  • Sanitization: No explicit logic or instructions are provided to sanitize external content before the agent processes it in its context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:21 PM
Security Audit — agent-trust-hub — botpress