greenhouse-harvest
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@membranehq/clipackage from the official NPM registry to facilitate platform interactions. - [COMMAND_EXECUTION]: The skill utilizes several CLI commands via
membraneandnpxto manage authentication, establish connections to the Greenhouse API, and execute remote actions. These commands are part of the intended integration workflow for the Greenhouse Harvest service. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from the external Greenhouse Harvest API, which could potentially contain untrusted content.
- Ingestion points: Data returned from Greenhouse Harvest endpoints via
membrane action runormembrane request(SKILL.md). - Boundary markers: No specific delimiters or "ignore" instructions are defined for the received data in the skill instructions.
- Capability inventory: The skill can execute network requests and API actions through the Membrane CLI (SKILL.md).
- Sanitization: The instructions do not specify explicit sanitization logic, relying on the underlying agent platform's default handling of tool outputs.
Audit Metadata