instatus

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package globally using npm. This package is provided by the vendor to interact with their platform and is necessary for the skill's operations.
  • [COMMAND_EXECUTION]: The instructions require the execution of multiple shell commands via the membrane CLI tool, including membrane login for authentication, membrane connect for account linking, and membrane action run for data operations.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection attacks.
  • Ingestion points: Data retrieved from Instatus (e.g., incident descriptions, component names, or metrics) enters the agent's context through the membrane action run command.
  • Boundary markers: The skill does not provide any specific delimiters or instructions to help the agent distinguish between trusted instructions and potentially untrusted data from Instatus.
  • Capability inventory: The agent has the ability to execute CLI commands and modify external status page data, creating a functional path if the agent is manipulated by malicious content in an incident report.
  • Sanitization: There is no evidence of filtering, escaping, or validation of the content retrieved from the Instatus API before it is processed by the model.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 04:21 AM
Security Audit — agent-trust-hub — instatus