greenhouse-harvest

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package from the official NPM registry to facilitate platform interactions.
  • [COMMAND_EXECUTION]: The skill utilizes several CLI commands via membrane and npx to manage authentication, establish connections to the Greenhouse API, and execute remote actions. These commands are part of the intended integration workflow for the Greenhouse Harvest service.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from the external Greenhouse Harvest API, which could potentially contain untrusted content.
  • Ingestion points: Data returned from Greenhouse Harvest endpoints via membrane action run or membrane request (SKILL.md).
  • Boundary markers: No specific delimiters or "ignore" instructions are defined for the received data in the skill instructions.
  • Capability inventory: The skill can execute network requests and API actions through the Membrane CLI (SKILL.md).
  • Sanitization: The instructions do not specify explicit sanitization logic, relying on the underlying agent platform's default handling of tool outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 11:11 PM
Security Audit — agent-trust-hub — greenhouse-harvest