melissa-data

Pass

Audited by Gen Agent Trust Hub on May 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill employs the membrane CLI for managing service authentication and executing data operations.\n- [EXTERNAL_DOWNLOADS]: The instructions involve downloading the @membranehq/cli package from npm to enable core functionality.\n- [PROMPT_INJECTION]: Untrusted data from Melissa Data (such as identity and contact records) is ingested into the agent context via the membrane action run command, creating an indirect prompt injection surface. The ingestion points are the action results, while the skill's capabilities include action execution and dynamic creation; no boundary markers or sanitization steps are defined for the processed content.
Audit Metadata
Risk Level
SAFE
Analyzed
May 3, 2026, 09:48 PM