lemon-squeezy

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the Membrane CLI using the command npm install -g @membranehq/cli@latest. This is a package provided by the skill author's organization for interacting with their platform.
  • [COMMAND_EXECUTION]: The skill utilizes the membrane command-line interface to manage authentication, establish connections, and execute actions. These commands are executed by the agent to interact with the Lemon Squeezy API via Membrane's infrastructure.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from Lemon Squeezy, such as product lists, customer details, and subscription data, which are ingested into the agent's context. This creates a potential surface for indirect prompt injection if external data sources are compromised.
  • Ingestion points: Data retrieved from Lemon Squeezy through CLI actions like list-products and list-customers (SKILL.md).
  • Boundary markers: The instructions do not specify the use of delimiters or specific prompts to ignore embedded instructions in the retrieved data.
  • Capability inventory: The skill possesses the capability to execute CLI commands and make network requests via the Membrane proxy.
  • Sanitization: There is no mention of sanitization or validation of the content returned from the external API before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 04:29 PM
Security Audit — agent-trust-hub — lemon-squeezy