erpnext
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill utilizes the official Membrane CLI (
@membranehq/cli) for authentication and API proxying. This approach ensures that sensitive credentials are not handled directly by the agent or stored insecurely, aligning with the vendor's security architecture. - [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes data from an external ERPNext instance, which represents a surface for indirect prompt injection if the stored data contains malicious instructions.
- Ingestion points: Data retrieved from ERPNext documents, items, and customers via actions like
list-documentsorget-item(SKILL.md). - Boundary markers: Not defined. The instructions do not specify the use of delimiters for data retrieved from the API.
- Capability inventory: The skill has the capability to run actions and make proxy requests via the
membraneCLI. - Sanitization: Not specified. The skill relies on the underlying platform's safety guardrails for handling retrieved content.
Audit Metadata