mattermost

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the Membrane CLI (@membranehq/cli) from the npm registry. This is a vendor-provided tool required for the skill's functionality.
  • [COMMAND_EXECUTION]: The skill relies on shell commands via the membrane CLI to authenticate users, manage connections, and execute Mattermost actions. This is the intended operation for a CLI-based integration.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates an attack surface by ingesting untrusted data from Mattermost (such as channel posts) which could contain malicious instructions designed to influence the agent's behavior during subsequent steps.
  • Ingestion points: Data retrieved from Mattermost channels, users, and posts via membrane action run or membrane request commands.
  • Boundary markers: None explicitly defined in the skill instructions to delimit external content.
  • Capability inventory: The skill allows the agent to run defined actions (membrane action run) and perform arbitrary API requests (membrane request) on the Mattermost server.
  • Sanitization: The instructions do not specify sanitization or validation steps for content retrieved from the external API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:30 AM
Security Audit — agent-trust-hub — mattermost