font-awesome
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the Membrane CLI (
@membranehq/cli) from the official NPM registry to enable platform interactions. - [COMMAND_EXECUTION]: The skill executes various
membraneCLI commands for authentication, connection management, and running API actions. This includesmembrane login,membrane connection ensure, andmembrane action run. - [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection by interpolating user-supplied data into command arguments.
- Ingestion points: User-provided search queries for
intentand data forinputparameters are used in CLI commands (found inSKILL.md). - Boundary markers: The instructions lack specific boundary markers or escaping guidelines when interpolating user data into the CLI command templates.
- Capability inventory: The skill has the capability to perform network operations, including searching and executing actions on external APIs through the Membrane proxy.
- Sanitization: There is no evidence of explicit sanitization or validation of the user-provided strings before they are passed as arguments to the
membraneCLI tool.
Audit Metadata