google-cloud-ai-platform

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the membrane CLI tool to perform authentication, connect to connectors, and manage actions. This is the intended functional behavior of the skill.\n- [EXTERNAL_DOWNLOADS]: The skill instructions include installing the @membranehq/cli package from the official NPM registry. This package belongs to the skill's author (Membrane).\n- [REMOTE_CODE_EXECUTION]: The npx command is used to execute the latest version of the Membrane CLI directly. This is a standard vendor-supported method for using their tooling.\n- [PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection by accepting user-provided inputs for command arguments. Ingestion points: intents in action list and inputs in action run. Boundary markers: none specified in command templates. Capability inventory: includes the ability to run and create actions on the platform. Sanitization: none specified in the documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 07:38 PM