kvk

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill guides users to install the @membranehq/cli package from the official NPM registry. This is a vendor-provided tool necessary for the skill's operation.
  • [COMMAND_EXECUTION]: The instructions rely on executing various membrane CLI commands (e.g., membrane login, membrane connect, membrane action run) to interact with external services. These commands are part of the intended integration workflow.
  • [DATA_EXFILTRATION]: The skill possesses an indirect prompt injection surface because it processes data retrieved from the KVK API via the Membrane platform. While this is a standard integration pattern, data returned from external actions should be treated as untrusted if subsequently used in security-sensitive prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 12:03 PM