microsoft-entra-id
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the official Membrane CLI (
@membranehq/cli) from the NPM registry to facilitate platform interactions. - [COMMAND_EXECUTION]: The skill executes shell commands using the
membraneutility to manage authentication, establish connections, and perform directory operations. - [INDIRECT_PROMPT_INJECTION]: The skill creates a vulnerability surface by ingesting untrusted data from the Microsoft Entra ID environment.
- Ingestion points: Data retrieved from directory objects (users, groups, apps) via
membrane action runandmembrane request(SKILL.md). - Boundary markers: No explicit delimitation or instructions to ignore embedded content are provided in the prompt templates.
- Capability inventory: The skill possesses the ability to modify directory data and execute API requests through the
membrane action runandmembrane requestcommands. - Sanitization: There is no evidence of specific sanitization or validation performed on data returned from the Entra ID API before it is processed by the agent.
Audit Metadata