mobile-text-alerts
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
@membranehq/clipackage from the npm registry. This is an official tool provided by the vendor (Membrane) to facilitate integrations. - [COMMAND_EXECUTION]: The skill instructs the agent to execute various shell commands using the
membraneCLI, such asmembrane login,membrane connect, andmembrane action run. These are used to manage the lifecycle of the integration and execute tasks. - [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing external data from the Mobile Text Alerts API. While it lacks explicit boundary markers for the data returned by actions, the processing is handled through the Membrane platform's structured action system, which reduces the risk of direct execution of malicious instructions found in the data.
Audit Metadata