function

Warn

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: MEDIUMPROMPT_INJECTIONREMOTE_CODE_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [METADATA_POISONING]: The skill description refers to CRM entities (Deals, Persons, Leads), which contradicts the body text that links to MATLAB documentation and states a lack of information about the application's purpose.\n- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill instructions depend on npx @membranehq/cli@latest, which downloads and runs external code from the public NPM registry at runtime.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The instructions note that sensitive authentication credentials are saved locally at ~/.membrane/credentials.json.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data via service actions and schemas.\n
  • Ingestion points: Service connection actions and schemas (SKILL.md)\n
  • Boundary markers: Absent\n
  • Capability inventory: Shell command execution and network proxy requests via Membrane CLI\n
  • Sanitization: Absent
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 18, 2026, 03:41 AM
Security Audit — agent-trust-hub — function