compass-ai

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes the membrane CLI to handle authentication, connection management, and service interaction, which is consistent with its stated purpose.\n- [EXTERNAL_DOWNLOADS]: The skill installs the @membranehq/cli package from the public npm registry; this is a standard tool provided by the vendor for integration.\n- [DATA_EXFILTRATION]: Sensitive operations and API calls are conducted through Membrane's proxy service, ensuring that authentication tokens are managed server-side and are not exposed to the agent or local environment.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external API responses via the CLI. While this is an ingestion surface for untrusted content, no malicious patterns were identified.\n
  • Ingestion points: Output from membrane action list and membrane action run as described in SKILL.md.\n
  • Boundary markers: None.\n
  • Capability inventory: membrane CLI commands allowing network communication and data retrieval.\n
  • Sanitization: Not specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 03:20 AM