google-vertex-ai

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the Membrane CLI tool (@membranehq/cli) via npm. This is the official tool provided by the vendor to facilitate the integration and manage authentication server-side.
  • [COMMAND_EXECUTION]: The skill uses shell commands through the membrane CLI to manage user login, establish connections to Google Vertex AI, and execute specific API actions. These operations are restricted to the functionality of the integration.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests and processes data from external machine learning models and datasets via membrane action run and membrane request (SKILL.md). While documentation does not explicitly detail boundary markers or sanitization, this is an inherent risk of data-processing skills and is mitigated by the agent's core safety protocols.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 04:39 PM
Security Audit — agent-trust-hub — google-vertex-ai