enable-banking
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@membranehq/clipackage globally from the NPM registry. - [COMMAND_EXECUTION]: The skill relies on executing the
membraneCLI tool for authentication, connection management, and running banking actions. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from the Enable Banking API, which constitutes an attack surface for indirect prompt injection.
- Ingestion points: External data enters the agent context through the outputs of
membrane action runandmembrane requestas described inSKILL.md. - Boundary markers: No explicit delimiters or warnings are provided to the agent to treat API responses as untrusted content.
- Capability inventory: The skill uses the
membraneCLI to perform network operations and local command execution. - Sanitization: There are no documented steps for sanitizing or validating the schema of the data returned from the external API before processing.
Audit Metadata