chatbot-builder

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the Membrane CLI package (@membranehq/cli) from the public NPM registry to facilitate interaction with the Membrane platform.
  • [COMMAND_EXECUTION]: The skill executes shell commands using the membrane CLI to manage user authentication, establish connections to third-party services, and execute API actions.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from the Chatbot Builder service which may contain untrusted content. 1. Ingestion points: Data is ingested through actions such as 'list-opportunities', 'get-contact', and 'list-flows' as defined in SKILL.md. 2. Boundary markers: The instructions do not define delimiters or specific 'ignore' instructions for the agent when processing external content. 3. Capability inventory: The skill has the ability to execute shell commands and perform network operations via the Membrane CLI. 4. Sanitization: There is no evidence of sanitization or validation of the external API data before it is presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 01:00 AM
Security Audit — agent-trust-hub — chatbot-builder