bubble
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions include installing the Membrane CLI tool (@membranehq/cli) from the npm registry. This is a vendor-owned resource used for platform authentication and API interaction.
- [COMMAND_EXECUTION]: The skill utilizes the 'membrane' CLI to perform several operations including authentication (membrane login), connection management (membrane connection), and executing Bubble-specific actions or raw API requests.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it retrieves data from an external source (Bubble). 1. Ingestion points: Data retrieved from Bubble applications via actions such as list-records and get-record (SKILL.md). 2. Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands in the retrieved data. 3. Capability inventory: The skill has command execution capabilities through the Membrane CLI to modify Bubble data (SKILL.md). 4. Sanitization: No explicit sanitization or validation of the retrieved Bubble data is described in the skill.
Audit Metadata