lemon-squeezy
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing the Membrane CLI using the command
npm install -g @membranehq/cli@latest. This is a package provided by the skill author's organization for interacting with their platform. - [COMMAND_EXECUTION]: The skill utilizes the
membranecommand-line interface to manage authentication, establish connections, and execute actions. These commands are executed by the agent to interact with the Lemon Squeezy API via Membrane's infrastructure. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from Lemon Squeezy, such as product lists, customer details, and subscription data, which are ingested into the agent's context. This creates a potential surface for indirect prompt injection if external data sources are compromised.
- Ingestion points: Data retrieved from Lemon Squeezy through CLI actions like
list-productsandlist-customers(SKILL.md). - Boundary markers: The instructions do not specify the use of delimiters or specific prompts to ignore embedded instructions in the retrieved data.
- Capability inventory: The skill possesses the capability to execute CLI commands and make network requests via the Membrane proxy.
- Sanitization: There is no mention of sanitization or validation of the content returned from the external API before it is processed by the agent.
Audit Metadata