directus

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package globally via NPM, which is a tool provided by the vendor to facilitate platform interaction.
  • [COMMAND_EXECUTION]: The skill frequently invokes the membrane CLI to handle authentication, connection management, and action execution. These commands are essential for the skill's primary function.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external Directus collections, creating a potential surface for indirect prompt injection if those collections contain malicious instructions.
  • Ingestion points: Results from membrane action run and membrane request which fetch data from Directus API endpoints.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the fetched data.
  • Capability inventory: The agent has the ability to execute shell commands using the membrane CLI, which can be used to read or modify external data.
  • Sanitization: There is no mention of sanitization or validation logic to filter potentially malicious content from the API responses before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:15 PM
Security Audit — agent-trust-hub — directus