font-awesome

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the Membrane CLI (@membranehq/cli) from the official NPM registry to enable platform interactions.
  • [COMMAND_EXECUTION]: The skill executes various membrane CLI commands for authentication, connection management, and running API actions. This includes membrane login, membrane connection ensure, and membrane action run.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection by interpolating user-supplied data into command arguments.
  • Ingestion points: User-provided search queries for intent and data for input parameters are used in CLI commands (found in SKILL.md).
  • Boundary markers: The instructions lack specific boundary markers or escaping guidelines when interpolating user data into the CLI command templates.
  • Capability inventory: The skill has the capability to perform network operations, including searching and executing actions on external APIs through the Membrane proxy.
  • Sanitization: There is no evidence of explicit sanitization or validation of the user-provided strings before they are passed as arguments to the membrane CLI tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 05:32 PM
Security Audit — agent-trust-hub — font-awesome