brandfetch

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package via NPM. This is the official command-line interface for the Membrane platform, which is the vendor context for this skill.
  • [COMMAND_EXECUTION]: The skill relies on executing membrane CLI commands to manage authentication (membrane login), connection lifecycle (membrane connection ensure), and API interaction (membrane action run, membrane request). These commands are necessary for the skill's stated purpose of integrating with Brandfetch.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from the external Brandfetch API, creating a surface for potential indirect prompt injection if the API returns malicious content.
  • Ingestion points: Data retrieved via membrane action run and membrane request commands as described in SKILL.md.
  • Boundary markers: The instructions do not specify explicit delimiters or boundary markers for the data returned by the API.
  • Capability inventory: The skill uses the membrane CLI to perform network requests and manage remote assets.
  • Sanitization: No specific sanitization or filtering logic is provided in the instructional text for handling retrieved brand assets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 12:07 PM
Security Audit — agent-trust-hub — brandfetch