manychat

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions include installing the @membranehq/cli package from the npm registry. This is the primary tool for interacting with the Membrane platform.- [COMMAND_EXECUTION]: The skill uses shell commands via the membrane CLI to perform authentication (membrane login), manage connections (membrane connection ensure), and execute API actions (membrane action run, membrane request).- [INDIRECT_PROMPT_INJECTION]: The skill has a potential surface for indirect prompt injection, as it processes data from an external platform (ManyChat) which could contain malicious instructions.
  • Ingestion points: Data retrieved from ManyChat subscribers, flows, or broadcasts, and user-provided intents for action discovery.
  • Boundary markers: None explicitly defined in the SKILL.md instructions.
  • Capability inventory: Execution of API actions and raw HTTP requests via the membrane CLI.
  • Sanitization: No specific sanitization logic is provided in the skill documentation; it relies on the underlying platform's handling of actions and connections.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 03:33 PM
Security Audit — agent-trust-hub — manychat