bridge
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@membranehq/clipackage globally from the NPM registry and utilizesnpxfor executing connection checks. - [COMMAND_EXECUTION]: The skill uses the
membranecommand-line utility to manage authentication, establish connections, and execute actions or raw API requests against the Bridge service. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill processes various data types from the Bridge platform, including meeting transcriptions, summaries, action items, and analytics (SKILL.md).
- Boundary markers: The instructions do not define specific delimiters or security boundaries for the agent when processing data returned from the Bridge API.
- Capability inventory: The skill allows for command execution via the Membrane CLI and direct HTTP request proxying to the Bridge API endpoints.
- Sanitization: There is no explicit sanitization or validation logic described for the data ingested from the external service before it is presented to the agent's context.
Audit Metadata