coterie-insurance

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill represents an indirect prompt injection surface because it dynamically ingests action schemas and descriptions via the membrane action list command.
  • Ingestion points: Action names, descriptions, and input/output schemas are fetched from the Membrane platform at runtime.
  • Boundary markers: None explicitly defined in the prompt instructions for isolating these schemas.
  • Capability inventory: The skill allows executing shell commands (membrane action run, membrane request) and performing network operations through the Membrane proxy.
  • Sanitization: The instructions do not specify explicit sanitization or validation of the fetched metadata before the agent processes it.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli package from the NPM registry. This is a standard vendor-provided tool for interacting with the platform.
  • [COMMAND_EXECUTION]: The skill relies on executing the membrane CLI to manage connections, search for actions, and interact with the Coterie Insurance API. This includes passing JSON parameters and handling command output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 06:37 AM
Security Audit — agent-trust-hub — coterie-insurance