datawrapper

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to download and install the @membranehq/cli package from the NPM registry. This is a vendor-provided tool required for the skill to interact with the Membrane platform.
  • [COMMAND_EXECUTION]: The skill uses shell commands to invoke the membrane CLI for managing connections, searching for Datawrapper actions, and executing API requests. These commands are the primary mechanism for the skill's functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from the Datawrapper API, such as chart metadata and action schemas.
  • Ingestion points: Data enters the agent context through membrane action list, membrane action run, and membrane request outputs.
  • Boundary markers: The instructions do not specify explicit boundary markers for the data returned from the CLI.
  • Capability inventory: The skill can execute shell commands (membrane) and make network requests via the proxy.
  • Sanitization: No specific sanitization of Datawrapper responses is described in the prompt instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:03 AM
Security Audit — agent-trust-hub — datawrapper