erpnext

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill utilizes the official Membrane CLI (@membranehq/cli) for authentication and API proxying. This approach ensures that sensitive credentials are not handled directly by the agent or stored insecurely, aligning with the vendor's security architecture.
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes data from an external ERPNext instance, which represents a surface for indirect prompt injection if the stored data contains malicious instructions.
  • Ingestion points: Data retrieved from ERPNext documents, items, and customers via actions like list-documents or get-item (SKILL.md).
  • Boundary markers: Not defined. The instructions do not specify the use of delimiters for data retrieved from the API.
  • Capability inventory: The skill has the capability to run actions and make proxy requests via the membrane CLI.
  • Sanitization: Not specified. The skill relies on the underlying platform's safety guardrails for handling retrieved content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 08:46 AM
Security Audit — agent-trust-hub — erpnext