fountain

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Recommends the installation and use of the @membranehq/cli package from the public NPM registry. This is the official command-line tool provided by the vendor (membranedev) for managing connections and API actions.
  • [COMMAND_EXECUTION]: Instructs the agent to execute shell commands using the membrane CLI to authenticate users, manage cloud-based connections, and run remote actions or proxy requests to the Fountain API.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection because it retrieves and acts upon external data from Fountain screenplay documents.
  • Ingestion points: Screenplay content, project records, and metadata retrieved via membrane action run and membrane request commands (found in SKILL.md).
  • Boundary markers: Absent; the instructions do not include specific delimiters or instructions to ignore embedded commands within the retrieved data.
  • Capability inventory: The skill enables the agent to perform write operations and arbitrary API requests (membrane action run, membrane request).
  • Sanitization: Absent; there are no requirements for sanitizing or validating retrieved data before it is processed or used to determine subsequent agent actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 12:30 AM
Security Audit — agent-trust-hub — fountain