hashnode
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill guides the user to install the
@membranehq/clipackage from the npm registry to enable interaction with the Membrane platform. - [COMMAND_EXECUTION]: The skill executes
membraneCLI commands for authentication, connection management, action listing, and API request proxying. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill fetches data from Hashnode, including user profiles, blog posts, and comments, which are then processed by the agent.
- Boundary markers: The skill instructions do not incorporate specific delimiters or boundary instructions to prevent the agent from interpreting instructions contained within retrieved external content.
- Capability inventory: The agent has the capability to perform actions such as
add-comment,update-post, andpublish-post, and can make arbitrary requests via themembrane requestproxy. - Sanitization: No explicit content sanitization or validation mechanisms are described for the data ingested from the Hashnode API.
Audit Metadata