hologram
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the Membrane CLI global package (
@membranehq/cli) from the official NPM registry to facilitate communication with the Hologram API. This is standard behavior for this vendor's ecosystem. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external sources (Hologram IoT devices and account records). This external data is untrusted and could potentially contain malicious content intended to influence the agent's behavior. However, this is a standard risk for all data-fetching skills, and no specific exploitable patterns were identified.
- Ingestion points: Data returned from
membrane action runandmembrane requestcalls. - Boundary markers: None explicitly defined in the prompt templates; the agent receives raw data from the CLI.
- Capability inventory: The skill allows network requests and action execution through the
membraneCLI. - Sanitization: None described; the skill relies on the agent's native safety filters to handle processed content.
Audit Metadata