centra
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the Membrane CLI (
@membranehq/cli) from the official npm registry. This is a vendor-owned tool required for the skill to function. - [COMMAND_EXECUTION]: The agent uses the
membranecommand-line interface to perform authentication, search for API actions, and execute requests against the Centra platform. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the Centra e-commerce platform which could contain malicious instructions.
- Ingestion points: Data retrieved via
membrane action runormembrane request(e.g., product descriptions, order notes, customer details). - Boundary markers: None provided in the prompt instructions to help the agent distinguish between data and instructions.
- Capability inventory: The skill can perform state-changing operations like
cancel-order,create-product, andupdate-customervia the CLI. - Sanitization: There is no explicit requirement for the agent to sanitize or validate the content of the data retrieved from the API.
Audit Metadata