fastfield-mobile-forms

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli package from the npm registry to interact with the Membrane platform. This is a standard dependency for the skill's functionality.
  • [COMMAND_EXECUTION]: The skill provides instructions for executing shell commands using the membrane CLI. These commands facilitate authentication, connection management, and data retrieval from the FastField Mobile Forms API.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from FastField Mobile Forms, which represents a potential attack surface for indirect prompt injection if the external content is not handled carefully.
  • Ingestion points: Data is ingested through membrane action run and membrane request commands, which fetch records and form details from the external API.
  • Boundary markers: The instructions do not specify the use of delimiters or specific prompts to separate untrusted API data from agent instructions.
  • Capability inventory: The skill has the capability to execute shell commands and make network requests via the Membrane CLI proxy.
  • Sanitization: There is no explicit mention of sanitization or validation logic for the content retrieved from the FastField API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:35 AM
Security Audit — agent-trust-hub — fastfield-mobile-forms