nasdaq-data-link

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli tool from the npm registry. This is a standard dependency for the vendor's platform.
  • [COMMAND_EXECUTION]: The skill makes extensive use of the membrane command-line tool to perform login, connection management, and data retrieval actions. These commands are necessary for the skill's primary functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads financial and alternative data from Nasdaq Data Link, which represents an indirect prompt injection surface as the agent processes data from an external source.
  • Ingestion points: External data is ingested through the membrane action run and membrane request commands.
  • Boundary markers: Not present; the skill does not specify delimiters to separate external data from system instructions.
  • Capability inventory: The agent can execute shell commands via the membrane CLI and make network requests through a proxy.
  • Sanitization: None explicitly mentioned; the agent relies on its inherent safety guardrails when processing the returned dataset content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 03:30 PM
Security Audit — agent-trust-hub — nasdaq-data-link