bubble

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions include installing the Membrane CLI tool (@membranehq/cli) from the npm registry. This is a vendor-owned resource used for platform authentication and API interaction.
  • [COMMAND_EXECUTION]: The skill utilizes the 'membrane' CLI to perform several operations including authentication (membrane login), connection management (membrane connection), and executing Bubble-specific actions or raw API requests.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it retrieves data from an external source (Bubble). 1. Ingestion points: Data retrieved from Bubble applications via actions such as list-records and get-record (SKILL.md). 2. Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands in the retrieved data. 3. Capability inventory: The skill has command execution capabilities through the Membrane CLI to modify Bubble data (SKILL.md). 4. Sanitization: No explicit sanitization or validation of the retrieved Bubble data is described in the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 08:28 AM
Security Audit — agent-trust-hub — bubble