calendly
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
@membranehq/clipackage from the NPM registry. This is an official tool provided by the skill author (membranedev) to facilitate integration with the Membrane platform. - [COMMAND_EXECUTION]: The skill instructions involve executing various
membraneCLI commands to manage authentication, establish connections to Calendly, and run API actions. These commands are standard for the tool's operation. - [INDIRECT_PROMPT_INJECTION]: The skill exposes the agent to data fetched from the external Calendly API (such as event names, invitee details, and descriptions). This data could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: Data retrieved from Calendly via the
membrane action runandmembrane requestcommands, specifically for actions likelist-scheduled-eventsandlist-event-invitees. - Boundary markers: The instructions do not define specific delimiters or warnings to ignore instructions embedded in the external data.
- Capability inventory: The skill can perform network operations and execute platform actions via the Membrane CLI.
- Sanitization: No explicit sanitization or validation of the external API responses is mentioned in the skill instructions.
Audit Metadata