microsoft-dynamics-365-business-central
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the
@membranehq/clipackage from the NPM registry. This is a vendor-provided tool used to facilitate communication with the integration service. - [COMMAND_EXECUTION]: The instructions involve executing various shell commands via the
membraneCLI, includinglogin,connection ensure, andaction run. These commands are used to manage authentication and interact with the Business Central API. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external Business Central records (such as General Ledger entries, employee lists, and invoices), creating a potential surface for indirect prompt injection.
- Ingestion points: Data is retrieved from Business Central through the
membrane action runandmembrane requestcommands described inSKILL.md. - Boundary markers: The instructions do not specify the use of delimiters or specific safety prompts to wrap the retrieved data.
- Capability inventory: The skill can execute pre-defined actions and perform raw API requests via the Membrane proxy.
- Sanitization: There is no mention of sanitization or validation routines for the data returned from the external API before it is processed by the agent.
Audit Metadata