cobalt

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use the membrane command-line interface to manage authentication, establish connections, and execute actions against the Cobalt API.\n- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli package from the public NPM registry, which is a standard procedure for utilizing the Membrane integration framework.\n- [INDIRECT_PROMPT_INJECTION]: \n
  • Ingestion points: The skill retrieves external data such as pentest findings, activity logs, and assets from the Cobalt platform (e.g., via list-findings or get-finding).\n
  • Boundary markers: There are no explicit delimiters or instructions provided to isolate or ignore potential instructions embedded within the retrieved data.\n
  • Capability inventory: The skill includes write capabilities through membrane action run and raw API requests (membrane request), which could be leveraged if malicious data is processed.\n
  • Sanitization: No explicit sanitization or validation of external content is defined in the instructions.\n- [METADATA_POISONING]: There is an inconsistency in the skill's documentation; the overview describes it as a tool for managing "customer support interactions" and "tickets," while the provided actions and platform details are strictly focused on "pentests," "findings," and "vulnerability management."
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:52 AM
Security Audit — agent-trust-hub — cobalt