calendly

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli package from the NPM registry. This is an official tool provided by the skill author (membranedev) to facilitate integration with the Membrane platform.
  • [COMMAND_EXECUTION]: The skill instructions involve executing various membrane CLI commands to manage authentication, establish connections to Calendly, and run API actions. These commands are standard for the tool's operation.
  • [INDIRECT_PROMPT_INJECTION]: The skill exposes the agent to data fetched from the external Calendly API (such as event names, invitee details, and descriptions). This data could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: Data retrieved from Calendly via the membrane action run and membrane request commands, specifically for actions like list-scheduled-events and list-event-invitees.
  • Boundary markers: The instructions do not define specific delimiters or warnings to ignore instructions embedded in the external data.
  • Capability inventory: The skill can perform network operations and execute platform actions via the Membrane CLI.
  • Sanitization: No explicit sanitization or validation of the external API responses is mentioned in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 05:14 AM
Security Audit — agent-trust-hub — calendly