mux

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli package via npm. This is a vendor-provided tool used to facilitate communication with the Membrane platform.
  • [COMMAND_EXECUTION]: The instructions utilize various membrane CLI commands (e.g., membrane login, membrane connection ensure, membrane action run) to interact with Mux data and manage connections. These are standard operations for the tool's intended use.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external Mux API endpoints (Assets, Incidents, Metrics). This creates a surface where instructions embedded in Mux data could potentially influence agent behavior.
  • Ingestion points: Data returned from membrane action run and membrane request commands targeting Mux APIs (SKILL.md).
  • Boundary markers: No specific boundary markers or prompt delimiters are defined in the instructions to separate external data from agent instructions.
  • Capability inventory: The skill can execute Mux actions and proxy requests, which includes capabilities to read, create, and modify video assets and streaming configurations (SKILL.md).
  • Sanitization: The instructions do not specify sanitization or filtering logic for the data retrieved from Mux.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 07:31 PM
Security Audit — agent-trust-hub — mux