heroku
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by ingesting and acting upon data from the Heroku environment.
- Ingestion points: Data enters the agent's context through action outputs (e.g.,
list-apps,get-config-vars,list-releases) and raw API responses viamembrane request. - Boundary markers: The instructions do not define specific delimiters or instructions for the agent to ignore potentially malicious content embedded in Heroku logs, metadata, or configuration values.
- Capability inventory: The skill provides significant capabilities to modify production infrastructure, including creating apps (
create-app), updating settings (update-app), and executing arbitrary API requests via the proxy. - Sanitization: There is no explicit sanitization of the data retrieved from the Heroku API before it is processed by the agent.
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@membranehq/clipackage from the official NPM registry. This is a standard installation of a vendor-provided tool used to facilitate the integration. - [COMMAND_EXECUTION]: The skill utilizes the
membranecommand-line interface to perform all operations, including authentication (membrane login), connection management (membrane connection ensure), and resource manipulation (membrane action run).
Audit Metadata