imagekitio

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the Membrane CLI via npm install -g @membranehq/cli@latest. This is a standard procedure to install the vendor's official command-line tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from ImageKit.io, which can serve as a vector for indirect prompt injection if external metadata contains malicious instructions.
  • Ingestion points: Data is ingested through actions such as list-files, get-file-details, and get-file-metadata mentioned in SKILL.md.
  • Boundary markers: There are no explicit instructions or delimiters provided to help the agent distinguish between data and instructions within the retrieved metadata.
  • Capability inventory: The skill allows the agent to perform write operations, including rename-file, move-file, and delete-file, as well as arbitrary API requests via membrane request.
  • Sanitization: No sanitization or filtering of the external file metadata is described in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 12:50 PM
Security Audit — agent-trust-hub — imagekitio