hashnode

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill guides the user to install the @membranehq/cli package from the npm registry to enable interaction with the Membrane platform.
  • [COMMAND_EXECUTION]: The skill executes membrane CLI commands for authentication, connection management, action listing, and API request proxying.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill fetches data from Hashnode, including user profiles, blog posts, and comments, which are then processed by the agent.
  • Boundary markers: The skill instructions do not incorporate specific delimiters or boundary instructions to prevent the agent from interpreting instructions contained within retrieved external content.
  • Capability inventory: The agent has the capability to perform actions such as add-comment, update-post, and publish-post, and can make arbitrary requests via the membrane request proxy.
  • Sanitization: No explicit content sanitization or validation mechanisms are described for the data ingested from the Hashnode API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:05 PM
Security Audit — agent-trust-hub — hashnode