kvk
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the Membrane CLI (
@membranehq/cli) using NPM and usesnpxto run connection commands. These are official vendor tools provided by the Membrane platform for API integration. - [COMMAND_EXECUTION]: The instructions involve executing various
membraneCLI commands to log in, establish connections to the KVK domain, and run business actions. - [INDIRECT_PROMPT_INJECTION]: The skill acts as an interface for KVK data, presenting a surface for indirect prompt injection from API responses.
- Ingestion points: Data retrieved from the KVK API, including company profiles, addresses, and business activities via
membrane requestandmembrane action run(found in SKILL.md). - Boundary markers: The instructions do not specify the use of delimiters or instructions to ignore embedded commands in the data returned from the API.
- Capability inventory: The skill uses the
membraneCLI for shell-based API interaction, which includes network communication and data retrieval capabilities. - Sanitization: There is no mention of sanitizing or validating the business data returned by the KVK API before it is processed by the agent.
Audit Metadata