chatwoot

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user or agent to install the Membrane CLI (@membranehq/cli) from the official NPM registry to facilitate the integration.
  • [COMMAND_EXECUTION]: The instructions involve executing several shell commands using the membrane CLI, including membrane login, membrane connection ensure, membrane action list, and membrane action run. These commands are used to manage authentication and interact with the Chatwoot API.
  • [INDIRECT_PROMPT_INJECTION]: The skill uses a natural language query via the --intent flag in the membrane action list command to discover available API actions.
  • Ingestion points: The --intent flag in SKILL.md (e.g., membrane action list --intent "QUERY").
  • Boundary markers: None explicitly defined for the search string.
  • Capability inventory: Includes network access, connection management, and execution of Chatwoot API actions via the CLI.
  • Sanitization: The skill relies on the CLI's internal processing of the search string.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 03:31 AM
Security Audit — agent-trust-hub — chatwoot