learndash

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli package from the npm registry to enable communication with the Membrane platform.
  • [COMMAND_EXECUTION]: The skill executes the membrane command-line utility for authentication (membrane login), connection management (membrane connection ensure), and executing LearnDash-related actions.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external LearnDash sources, establishing a surface for indirect prompt injection.
  • Ingestion points: Untrusted data enters the agent context via action outputs (e.g., list-courses, get-course) and direct requests via the membrane request proxy as described in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters or warnings for the agent to disregard potential instructions embedded in the LearnDash data.
  • Capability inventory: The skill possesses significant write capabilities, including the ability to create, update, and delete courses and groups, and manage user enrollments through the membrane CLI.
  • Sanitization: No explicit sanitization or content validation mechanisms are implemented for data retrieved from the external API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 06:29 PM
Security Audit — agent-trust-hub — learndash