cobalt
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use the
membranecommand-line interface to manage authentication, establish connections, and execute actions against the Cobalt API.\n- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the@membranehq/clipackage from the public NPM registry, which is a standard procedure for utilizing the Membrane integration framework.\n- [INDIRECT_PROMPT_INJECTION]: \n - Ingestion points: The skill retrieves external data such as pentest findings, activity logs, and assets from the Cobalt platform (e.g., via
list-findingsorget-finding).\n - Boundary markers: There are no explicit delimiters or instructions provided to isolate or ignore potential instructions embedded within the retrieved data.\n
- Capability inventory: The skill includes write capabilities through
membrane action runand raw API requests (membrane request), which could be leveraged if malicious data is processed.\n - Sanitization: No explicit sanitization or validation of external content is defined in the instructions.\n- [METADATA_POISONING]: There is an inconsistency in the skill's documentation; the overview describes it as a tool for managing "customer support interactions" and "tickets," while the provided actions and platform details are strictly focused on "pentests," "findings," and "vulnerability management."
Audit Metadata