livekit

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the @membranehq/cli package globally via npm to interact with the Membrane platform.
  • [COMMAND_EXECUTION]: The skill relies on executing terminal commands through the membrane CLI for authentication, connection management, and performing LiveKit actions.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes real-time communication data (rooms, tracks, and participants) from LiveKit, which could contain untrusted content capable of influencing agent behavior.
  • Ingestion points: Data returned from shell commands such as membrane action run and membrane request (SKILL.md).
  • Boundary markers: Absent; there are no instructions to the agent to treat API output as data rather than instructions, nor are there delimiters used.
  • Capability inventory: The skill provides capabilities to execute shell commands, manage authenticated connections, and perform network requests (SKILL.md).
  • Sanitization: Absent; the skill does not define any validation or escaping for the data fetched from the external API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:42 PM
Security Audit — agent-trust-hub — livekit