Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Recommends installing the
@membranehq/clitool from the npm registry. This is the official CLI for the platform referenced in the skill metadata and homepage, developed by the vendor. - [COMMAND_EXECUTION]: Uses the
membraneCLI to perform authentication, manage LinkedIn connections, and execute actions. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from LinkedIn, creating a surface for potential indirect instructions from external profiles or posts.
- Ingestion points: Fetches external content via actions like
list-posts,list-comments, andget-postdescribed inSKILL.md. - Boundary markers: None explicitly mentioned in the skill instructions to delimit external content for the agent.
- Capability inventory: The skill can modify external state through actions like
create-postanddelete-postvia themembrane action runcommand inSKILL.md. - Sanitization: No specific sanitization or filtering logic is mentioned for processing data fetched from the API.
Audit Metadata