docusign
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
@membranehq/clipackage from the NPM registry. This package is part of the official tooling provided by the vendor. - [COMMAND_EXECUTION]: The instructions involve executing various commands using the
membraneCLI to manage user login, connections, and DocuSign actions. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: Data ingested from DocuSign envelopes, templates, and documents (e.g., via
list-envelopes,get-envelope,get-envelope-form-data). - Boundary markers: Not present; the instructions do not include specific delimiters or warnings for the agent to ignore instructions embedded in the external data.
- Capability inventory: The skill has the ability to make network requests via the
membrane requestcommand and perform file operations such as downloading documents. - Sanitization: None mentioned for the data retrieved from external DocuSign sources.
Audit Metadata