dub
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill directs the user to install the Membrane CLI (
@membranehq/cli) using npm. This is a standard installation for the vendor's platform utility. - [COMMAND_EXECUTION]: The skill relies on the
membraneCLI to perform actions, manage connections, and make authenticated API requests to the Dub platform. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from the Dub API, which creates a potential surface for indirect prompt injection if the data sources (like link descriptions or analytics events) are manipulated.
- Ingestion points: API responses from Dub regarding links, workspaces, events, and analytics.
- Boundary markers: None provided in the instructions.
- Capability inventory: Shell command execution via the
membraneCLI, including the ability to run actions and proxy API requests. - Sanitization: No explicit validation or filtering of external API data is mentioned.
Audit Metadata