hotmart
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the official Membrane command-line interface using
npm install -g @membranehq/cli@latest. This is a standard procedure for using the Membrane platform and the package belongs to the vendor's ecosystem. - [COMMAND_EXECUTION]: The skill requires the execution of multiple shell commands using the
membraneCLI (e.g.,membrane login,membrane connection ensure,membrane action list). These commands facilitate authentication and interaction with the Hotmart API through Membrane's infrastructure. - [INDIRECT_PROMPT_INJECTION]: The skill specifies how the agent should handle external data and user-provided intents (e.g.,
membrane action list --intent "QUERY"). While this creates an ingestion point for untrusted data, it is a standard design for such integration tools and is handled by the platform's CLI logic.
Audit Metadata