kvk
Pass
Audited by Gen Agent Trust Hub on Apr 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill guides users to install the
@membranehq/clipackage from the official NPM registry. This is a vendor-provided tool necessary for the skill's operation. - [COMMAND_EXECUTION]: The instructions rely on executing various
membraneCLI commands (e.g.,membrane login,membrane connect,membrane action run) to interact with external services. These commands are part of the intended integration workflow. - [DATA_EXFILTRATION]: The skill possesses an indirect prompt injection surface because it processes data retrieved from the KVK API via the Membrane platform. While this is a standard integration pattern, data returned from external actions should be treated as untrusted if subsequently used in security-sensitive prompts.
Audit Metadata