jetbrains-marketplace
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to install the
@membranehq/clitool from the official NPM registry. This is a standard utility provided by the vendor for managing connections and API actions.\n- [COMMAND_EXECUTION]: The skill relies on themembranecommand-line interface to manage authentication, poll connection statuses, and execute actions. These commands are integral to the skill's primary functionality of bridging the agent with the IntelliJ environment.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from the JetBrains Marketplace API, which introduces a potential surface for indirect prompt injection.\n - Ingestion points: Data returned by
membrane action listandmembrane requestendpoints (such as plugin descriptions and review content) is brought into the agent's context.\n - Boundary markers: The instructions do not define specific delimiters or instructions to treat external API data as untrusted.\n
- Capability inventory: The skill possesses the ability to execute shell commands via the CLI and perform network operations via the Membrane proxy functionality.\n
- Sanitization: No explicit sanitization or filtering of the incoming external data is specified in the skill's instructions.
Audit Metadata