mux
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
@membranehq/clipackage via npm. This is a vendor-provided tool used to facilitate communication with the Membrane platform. - [COMMAND_EXECUTION]: The instructions utilize various
membraneCLI commands (e.g.,membrane login,membrane connection ensure,membrane action run) to interact with Mux data and manage connections. These are standard operations for the tool's intended use. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external Mux API endpoints (Assets, Incidents, Metrics). This creates a surface where instructions embedded in Mux data could potentially influence agent behavior.
- Ingestion points: Data returned from
membrane action runandmembrane requestcommands targeting Mux APIs (SKILL.md). - Boundary markers: No specific boundary markers or prompt delimiters are defined in the instructions to separate external data from agent instructions.
- Capability inventory: The skill can execute Mux actions and proxy requests, which includes capabilities to read, create, and modify video assets and streaming configurations (SKILL.md).
- Sanitization: The instructions do not specify sanitization or filtering logic for the data retrieved from Mux.
Audit Metadata