fastfield-mobile-forms
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
@membranehq/clipackage from the npm registry to interact with the Membrane platform. This is a standard dependency for the skill's functionality. - [COMMAND_EXECUTION]: The skill provides instructions for executing shell commands using the
membraneCLI. These commands facilitate authentication, connection management, and data retrieval from the FastField Mobile Forms API. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from FastField Mobile Forms, which represents a potential attack surface for indirect prompt injection if the external content is not handled carefully.
- Ingestion points: Data is ingested through
membrane action runandmembrane requestcommands, which fetch records and form details from the external API. - Boundary markers: The instructions do not specify the use of delimiters or specific prompts to separate untrusted API data from agent instructions.
- Capability inventory: The skill has the capability to execute shell commands and make network requests via the Membrane CLI proxy.
- Sanitization: There is no explicit mention of sanitization or validation logic for the content retrieved from the FastField API.
Audit Metadata