kanban-tool

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Installs the official @membranehq/cli package from the npm registry to manage platform interactions. This is an expected dependency from the skill's author.\n- [COMMAND_EXECUTION]: Executes membrane CLI commands to perform authentication, connection management, and task operations on Kanban Tool. These commands are standard for the tool's intended purpose.\n- [DATA_EXFILTRATION]: Exhibits an indirect prompt injection surface as it retrieves and processes task data from an external source and has the capability to write data back to the service.\n
  • Ingestion points: Data retrieved from boards and tasks via get-task and get-board actions.\n
  • Boundary markers: No explicit markers defined in the instructions for isolating external content.\n
  • Capability inventory: The skill uses membrane action run to perform data operations like creating or updating tasks.\n
  • Sanitization: Relies on the underlying platform's handling of action parameters and results.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 06:12 PM
Security Audit — agent-trust-hub — kanban-tool