kvk

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the Membrane CLI (@membranehq/cli) using NPM and uses npx to run connection commands. These are official vendor tools provided by the Membrane platform for API integration.
  • [COMMAND_EXECUTION]: The instructions involve executing various membrane CLI commands to log in, establish connections to the KVK domain, and run business actions.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as an interface for KVK data, presenting a surface for indirect prompt injection from API responses.
  • Ingestion points: Data retrieved from the KVK API, including company profiles, addresses, and business activities via membrane request and membrane action run (found in SKILL.md).
  • Boundary markers: The instructions do not specify the use of delimiters or instructions to ignore embedded commands in the data returned from the API.
  • Capability inventory: The skill uses the membrane CLI for shell-based API interaction, which includes network communication and data retrieval capabilities.
  • Sanitization: There is no mention of sanitizing or validating the business data returned by the KVK API before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 09:18 AM
Security Audit — agent-trust-hub — kvk