function
Warn
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: MEDIUMPROMPT_INJECTIONREMOTE_CODE_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [METADATA_POISONING]: The skill description refers to CRM entities (Deals, Persons, Leads), which contradicts the body text that links to MATLAB documentation and states a lack of information about the application's purpose.\n- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill instructions depend on
npx @membranehq/cli@latest, which downloads and runs external code from the public NPM registry at runtime.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The instructions note that sensitive authentication credentials are saved locally at~/.membrane/credentials.json.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data via service actions and schemas.\n - Ingestion points: Service connection actions and schemas (SKILL.md)\n
- Boundary markers: Absent\n
- Capability inventory: Shell command execution and network proxy requests via Membrane CLI\n
- Sanitization: Absent
Audit Metadata