mattermost
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the Membrane CLI (
@membranehq/cli) from the npm registry. This is a vendor-provided tool required for the skill's functionality. - [COMMAND_EXECUTION]: The skill relies on shell commands via the
membraneCLI to authenticate users, manage connections, and execute Mattermost actions. This is the intended operation for a CLI-based integration. - [INDIRECT_PROMPT_INJECTION]: The skill creates an attack surface by ingesting untrusted data from Mattermost (such as channel posts) which could contain malicious instructions designed to influence the agent's behavior during subsequent steps.
- Ingestion points: Data retrieved from Mattermost channels, users, and posts via
membrane action runormembrane requestcommands. - Boundary markers: None explicitly defined in the skill instructions to delimit external content.
- Capability inventory: The skill allows the agent to run defined actions (
membrane action run) and perform arbitrary API requests (membrane request) on the Mattermost server. - Sanitization: The instructions do not specify sanitization or validation steps for content retrieved from the external API.
Audit Metadata