docusign

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli package from the NPM registry. This package is part of the official tooling provided by the vendor.
  • [COMMAND_EXECUTION]: The instructions involve executing various commands using the membrane CLI to manage user login, connections, and DocuSign actions.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: Data ingested from DocuSign envelopes, templates, and documents (e.g., via list-envelopes, get-envelope, get-envelope-form-data).
  • Boundary markers: Not present; the instructions do not include specific delimiters or warnings for the agent to ignore instructions embedded in the external data.
  • Capability inventory: The skill has the ability to make network requests via the membrane request command and perform file operations such as downloading documents.
  • Sanitization: None mentioned for the data retrieved from external DocuSign sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 03:29 AM
Security Audit — agent-trust-hub — docusign