datawrapper
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to download and install the
@membranehq/clipackage from the NPM registry. This is a vendor-provided tool required for the skill to interact with the Membrane platform. - [COMMAND_EXECUTION]: The skill uses shell commands to invoke the
membraneCLI for managing connections, searching for Datawrapper actions, and executing API requests. These commands are the primary mechanism for the skill's functionality. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from the Datawrapper API, such as chart metadata and action schemas.
- Ingestion points: Data enters the agent context through
membrane action list,membrane action run, andmembrane requestoutputs. - Boundary markers: The instructions do not specify explicit boundary markers for the data returned from the CLI.
- Capability inventory: The skill can execute shell commands (
membrane) and make network requests via the proxy. - Sanitization: No specific sanitization of Datawrapper responses is described in the prompt instructions.
Audit Metadata