dataforseo
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@membranehq/clipackage from the public npm registry. This package is the official command-line tool for the Membrane platform, which the skill author (membranedev) maintains. - [COMMAND_EXECUTION]: The skill relies on shell commands using the
membraneCLI for managing user authentication, searching for API actions, and executing data requests. These commands are necessary for the skill's primary functionality and are executed within the scope of the Membrane environment. - [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from the DataForSEO API, including SERP (Search Engine Results Page) data and generated content, which could theoretically contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: Data retrieved from
membrane action run(e.g., SERP results, parsed page content) andmembrane requestresponses. - Boundary markers: None explicitly defined in the instructions to separate external data from system prompts.
- Capability inventory: The agent has the ability to execute shell commands via the
membraneCLI and perform network requests to thedataforseo.comandgetmembrane.comdomains. - Sanitization: No specific sanitization or filtering logic is described; the skill assumes standard agent guardrails are in place when processing retrieved data.
Audit Metadata