directus
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@membranehq/clipackage globally via NPM, which is a tool provided by the vendor to facilitate platform interaction. - [COMMAND_EXECUTION]: The skill frequently invokes the
membraneCLI to handle authentication, connection management, and action execution. These commands are essential for the skill's primary function. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external Directus collections, creating a potential surface for indirect prompt injection if those collections contain malicious instructions.
- Ingestion points: Results from
membrane action runandmembrane requestwhich fetch data from Directus API endpoints. - Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the fetched data.
- Capability inventory: The agent has the ability to execute shell commands using the
membraneCLI, which can be used to read or modify external data. - Sanitization: There is no mention of sanitization or validation logic to filter potentially malicious content from the API responses before processing.
Audit Metadata