learndash
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
@membranehq/clipackage from the npm registry to enable communication with the Membrane platform. - [COMMAND_EXECUTION]: The skill executes the
membranecommand-line utility for authentication (membrane login), connection management (membrane connection ensure), and executing LearnDash-related actions. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external LearnDash sources, establishing a surface for indirect prompt injection.
- Ingestion points: Untrusted data enters the agent context via action outputs (e.g.,
list-courses,get-course) and direct requests via themembrane requestproxy as described inSKILL.md. - Boundary markers: The instructions do not define specific delimiters or warnings for the agent to disregard potential instructions embedded in the LearnDash data.
- Capability inventory: The skill possesses significant write capabilities, including the ability to create, update, and delete courses and groups, and manage user enrollments through the
membraneCLI. - Sanitization: No explicit sanitization or content validation mechanisms are implemented for data retrieved from the external API.
Audit Metadata