centrifuge
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the Membrane CLI tool (
@membranehq/cli) using the npm package manager. This is a legitimate vendor resource used to facilitate the integration. - [COMMAND_EXECUTION]: The skill uses shell commands to interact with the Membrane CLI. These commands involve interpolating identifiers (like connection IDs and action IDs) and JSON data into shell arguments. This is the primary method of operation for this skill.
- [INDIRECT_PROMPT_INJECTION]: The skill interacts with external data from the Centrifuge platform, which creates a theoretical attack surface where malicious data from Centrifuge could influence agent behavior.
- Ingestion points: Data retrieved from the Centrifuge API via
membrane action runormembrane requestcommands (SKILL.md). - Boundary markers: None explicitly defined in the provided instruction templates.
- Capability inventory: The skill has the ability to execute shell commands and perform network operations via the Membrane proxy (SKILL.md).
- Sanitization: Not explicitly described; the skill relies on the Membrane platform for data handling and credential management.
Audit Metadata