bridge

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package globally from the NPM registry and utilizes npx for executing connection checks.
  • [COMMAND_EXECUTION]: The skill uses the membrane command-line utility to manage authentication, establish connections, and execute actions or raw API requests against the Bridge service.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill processes various data types from the Bridge platform, including meeting transcriptions, summaries, action items, and analytics (SKILL.md).
  • Boundary markers: The instructions do not define specific delimiters or security boundaries for the agent when processing data returned from the Bridge API.
  • Capability inventory: The skill allows for command execution via the Membrane CLI and direct HTTP request proxying to the Bridge API endpoints.
  • Sanitization: There is no explicit sanitization or validation logic described for the data ingested from the external service before it is presented to the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 01:12 AM
Security Audit — agent-trust-hub — bridge