melo
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the Membrane CLI via NPM (
@membranehq/cli). This is a standard dependency for the skill's functionality and originates from the vendor's ecosystem. - [COMMAND_EXECUTION]: The skill uses the
membraneCLI to perform operations like login, connection management, and action execution. These commands are necessary for the intended integration logic. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from the Melo API through the Membrane platform.
- Ingestion points: API responses from
membrane action runandmembrane request(SKILL.md). - Boundary markers: Not explicitly defined in the prompt instructions.
- Capability inventory: Execution of CLI commands to fetch and send data (SKILL.md).
- Sanitization: Relies on the agent's internal processing of CLI output.
Audit Metadata