flyio

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the official Membrane CLI package (@membranehq/cli) from the NPM registry. This is a standard installation procedure for the vendor's platform tools.
  • [COMMAND_EXECUTION]: The instructions utilize the membrane CLI to perform operations such as authentication, connection management, and executing actions against the Fly.io API. These commands are typical for the skill's stated purpose of managing Fly.io resources.
  • [INDIRECT_PROMPT_INJECTION]: The skill serves as a surface for indirect prompt injection by ingesting data from the Fly.io API (e.g., machine lists, secrets, logs) and processing it within the agent context.
  • Ingestion points: Data enters the context via membrane action run and membrane request outputs.
  • Boundary markers: None explicitly defined in the provided instructions.
  • Capability inventory: The skill has the capability to write to the file system or execute network requests via the Membrane CLI.
  • Sanitization: Relies on the underlying platform and LLM guardrails for processing external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:40 AM
Security Audit — agent-trust-hub — flyio