dub

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs the user to install the Membrane CLI (@membranehq/cli) using npm. This is a standard installation for the vendor's platform utility.
  • [COMMAND_EXECUTION]: The skill relies on the membrane CLI to perform actions, manage connections, and make authenticated API requests to the Dub platform.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from the Dub API, which creates a potential surface for indirect prompt injection if the data sources (like link descriptions or analytics events) are manipulated.
  • Ingestion points: API responses from Dub regarding links, workspaces, events, and analytics.
  • Boundary markers: None provided in the instructions.
  • Capability inventory: Shell command execution via the membrane CLI, including the ability to run actions and proxy API requests.
  • Sanitization: No explicit validation or filtering of external API data is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 10:05 PM
Security Audit — agent-trust-hub — dub