mlflow
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches and installs the
@membranehq/clipackage from the official NPM registry. This tool is the primary interface for the Membrane platform and is a vendor-provided resource. - [COMMAND_EXECUTION]: Executes various
membraneCLI commands to perform authentication, manage MLflow connections, and trigger remote actions. These commands are part of the intended functionality for interacting with the Membrane ecosystem. - [PRIVILEGE_ESCALATION]: The instructions recommend a global installation of the CLI tool (
npm install -g), which typically requires administrative or elevated system privileges on most operating systems. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external MLflow experiments, runs, and models. This creates a surface for potential indirect prompt injection if the source data contains malicious instructions.
- Ingestion points: Data retrieved from MLflow API endpoints via
membrane action runandmembrane requestcommands. - Boundary markers: No specific delimiters or instructions to ignore embedded content are present in the provided skill documentation.
- Capability inventory: The skill utilizes the
membraneCLI to perform network operations, manage system-wide authentication states, and execute remote functions. - Sanitization: The instructions do not specify any validation, filtering, or escaping mechanisms for the data retrieved from MLflow before it is processed by the agent.
Audit Metadata