enable-banking

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package globally from the NPM registry.
  • [COMMAND_EXECUTION]: The skill relies on executing the membrane CLI tool for authentication, connection management, and running banking actions.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from the Enable Banking API, which constitutes an attack surface for indirect prompt injection.
  • Ingestion points: External data enters the agent context through the outputs of membrane action run and membrane request as described in SKILL.md.
  • Boundary markers: No explicit delimiters or warnings are provided to the agent to treat API responses as untrusted content.
  • Capability inventory: The skill uses the membrane CLI to perform network operations and local command execution.
  • Sanitization: There are no documented steps for sanitizing or validating the schema of the data returned from the external API before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 04:40 PM
Security Audit — agent-trust-hub — enable-banking