centra

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the Membrane CLI (@membranehq/cli) from the official npm registry. This is a vendor-owned tool required for the skill to function.
  • [COMMAND_EXECUTION]: The agent uses the membrane command-line interface to perform authentication, search for API actions, and execute requests against the Centra platform.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the Centra e-commerce platform which could contain malicious instructions.
  • Ingestion points: Data retrieved via membrane action run or membrane request (e.g., product descriptions, order notes, customer details).
  • Boundary markers: None provided in the prompt instructions to help the agent distinguish between data and instructions.
  • Capability inventory: The skill can perform state-changing operations like cancel-order, create-product, and update-customer via the CLI.
  • Sanitization: There is no explicit requirement for the agent to sanitize or validate the content of the data retrieved from the API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 09:45 AM
Security Audit — agent-trust-hub — centra