microsoft-dynamics-365-business-central

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the @membranehq/cli package from the NPM registry. This is a vendor-provided tool used to facilitate communication with the integration service.
  • [COMMAND_EXECUTION]: The instructions involve executing various shell commands via the membrane CLI, including login, connection ensure, and action run. These commands are used to manage authentication and interact with the Business Central API.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external Business Central records (such as General Ledger entries, employee lists, and invoices), creating a potential surface for indirect prompt injection.
  • Ingestion points: Data is retrieved from Business Central through the membrane action run and membrane request commands described in SKILL.md.
  • Boundary markers: The instructions do not specify the use of delimiters or specific safety prompts to wrap the retrieved data.
  • Capability inventory: The skill can execute pre-defined actions and perform raw API requests via the Membrane proxy.
  • Sanitization: There is no mention of sanitization or validation routines for the data returned from the external API before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:20 AM
Security Audit — agent-trust-hub — microsoft-dynamics-365-business-central