mlflow

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches and installs the @membranehq/cli package from the official NPM registry. This tool is the primary interface for the Membrane platform and is a vendor-provided resource.
  • [COMMAND_EXECUTION]: Executes various membrane CLI commands to perform authentication, manage MLflow connections, and trigger remote actions. These commands are part of the intended functionality for interacting with the Membrane ecosystem.
  • [PRIVILEGE_ESCALATION]: The instructions recommend a global installation of the CLI tool (npm install -g), which typically requires administrative or elevated system privileges on most operating systems.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external MLflow experiments, runs, and models. This creates a surface for potential indirect prompt injection if the source data contains malicious instructions.
  • Ingestion points: Data retrieved from MLflow API endpoints via membrane action run and membrane request commands.
  • Boundary markers: No specific delimiters or instructions to ignore embedded content are present in the provided skill documentation.
  • Capability inventory: The skill utilizes the membrane CLI to perform network operations, manage system-wide authentication states, and execute remote functions.
  • Sanitization: The instructions do not specify any validation, filtering, or escaping mechanisms for the data retrieved from MLflow before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 05:14 AM
Security Audit — agent-trust-hub — mlflow