coterie-insurance
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill represents an indirect prompt injection surface because it dynamically ingests action schemas and descriptions via the
membrane action listcommand. - Ingestion points: Action names, descriptions, and input/output schemas are fetched from the Membrane platform at runtime.
- Boundary markers: None explicitly defined in the prompt instructions for isolating these schemas.
- Capability inventory: The skill allows executing shell commands (
membrane action run,membrane request) and performing network operations through the Membrane proxy. - Sanitization: The instructions do not specify explicit sanitization or validation of the fetched metadata before the agent processes it.
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
@membranehq/clipackage from the NPM registry. This is a standard vendor-provided tool for interacting with the platform. - [COMMAND_EXECUTION]: The skill relies on executing the
membraneCLI to manage connections, search for actions, and interact with the Coterie Insurance API. This includes passing JSON parameters and handling command output.
Audit Metadata