invoiced

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the @membranehq/cli tool from the npm registry to enable interaction with the Membrane platform. This is a standard setup step for this vendor's ecosystem.
  • [COMMAND_EXECUTION]: Uses the membrane CLI to perform operations such as authentication, connection management, and running actions against the Invoiced API. The commands are specific to the skill's purpose of managing financial data.
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes data from external Invoiced API endpoints, which represents a potential surface for indirect prompt injection.
  • Ingestion points: Data is ingested from Invoiced through actions like list-customers or direct membrane request calls in SKILL.md.
  • Boundary markers: Not explicitly defined in the skill instructions.
  • Capability inventory: The skill utilizes network access and CLI-based command execution for data retrieval and manipulation as seen in SKILL.md.
  • Sanitization: No explicit sanitization or validation of the retrieved API data is performed within the skill instructions, relying on the agent's internal processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:45 PM
Security Audit — agent-trust-hub — invoiced