microsoft-to-do
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the Membrane CLI tool from the public NPM registry using
npm install -g @membranehq/cli@latest. This is a legitimate utility provided by the vendor to facilitate secure API interactions. - [COMMAND_EXECUTION]: The skill's functionality relies on executing shell commands via the
membraneCLI. These commands perform authentication (membrane login), connection management (membrane connection ensure), and task operations (membrane action run). - [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection as it processes user-supplied intents and JSON data to interact with external APIs.
- Ingestion points: Data enters the system via the
--intentparameter inmembrane action listand the--inputparameter inmembrane action run(SKILL.md). - Boundary markers: No specific delimiters or warnings for the agent to ignore embedded instructions are present in the command templates.
- Capability inventory: The skill possesses the capability to execute shell commands and perform network operations through the vendor's proxy service.
- Sanitization: There are no instructions for sanitizing or escaping the data before it is passed to the CLI commands.
Audit Metadata