jetbrains-marketplace

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to install the @membranehq/cli tool from the official NPM registry. This is a standard utility provided by the vendor for managing connections and API actions.\n- [COMMAND_EXECUTION]: The skill relies on the membrane command-line interface to manage authentication, poll connection statuses, and execute actions. These commands are integral to the skill's primary functionality of bridging the agent with the IntelliJ environment.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from the JetBrains Marketplace API, which introduces a potential surface for indirect prompt injection.\n
  • Ingestion points: Data returned by membrane action list and membrane request endpoints (such as plugin descriptions and review content) is brought into the agent's context.\n
  • Boundary markers: The instructions do not define specific delimiters or instructions to treat external API data as untrusted.\n
  • Capability inventory: The skill possesses the ability to execute shell commands via the CLI and perform network operations via the Membrane proxy functionality.\n
  • Sanitization: No explicit sanitization or filtering of the incoming external data is specified in the skill's instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 07:56 AM
Security Audit — agent-trust-hub — jetbrains-marketplace