messagebird

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli package via npm to interface with the platform services.
  • [COMMAND_EXECUTION]: The skill utilizes the membrane CLI to perform operations such as logging in, connecting to services, and running automated actions.
  • [PROMPT_INJECTION]: The skill processes data from external communication channels (SMS, Voice, WhatsApp) which represents a surface for indirect instructions.
  • Ingestion points: Content retrieved from MessageBird messages and conversation participants via action run outputs.
  • Boundary markers: None explicitly implemented in the skill instructions.
  • Capability inventory: Subprocess execution via the membrane CLI and the ability to create new actions dynamically on the Membrane platform.
  • Sanitization: Relies on the platform's internal handling of action parameters and outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 06:12 PM
Security Audit — agent-trust-hub — messagebird