ifood

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli package via NPM. This is the official command-line utility for the Membrane platform, authored by the same vendor as the skill, and is essential for its operational logic.
  • [COMMAND_EXECUTION]: The instructions involve executing various subcommands of the membrane CLI for logging in, managing connections, and running actions. These operations are standard for the platform's intended use case and do not involve unauthorized privilege escalation or persistence mechanisms.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: Data retrieved from iFood through membrane action run and membrane request (as referenced in SKILL.md).
  • Boundary markers: No explicit delimiters are used in the provided examples to isolate external API data from the agent's internal prompt context.
  • Capability inventory: The skill possesses the capability to perform authenticated network requests and run platform-defined actions.
  • Sanitization: No explicit sanitization or filtering of external API data is described, which is typical for a data-integrator skill. The risk is considered low given the structured nature of the interaction.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 12:08 PM
Security Audit — agent-trust-hub — ifood