new-relic
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the Membrane CLI (@membranehq/cli) from the public npm registry. This is a standard procedure for using the vendor's integration platform.
- [COMMAND_EXECUTION]: The skill uses the membrane command-line tool for authentication, connection management, searching for actions, and executing New Relic requests. All commands are specific to the Membrane platform's core functionality.
- [REMOTE_CODE_EXECUTION]: The skill uses npx to execute the @membranehq/cli package directly. This allows the agent to run the CLI tool on-demand without requiring a persistent global installation.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data returned from New Relic APIs, which constitutes a potential attack surface for indirect prompt injection.
- Ingestion points: Data enters the agent's context through the output of membrane action run and membrane request commands, such as lists of applications, alert policies, and metric data.
- Boundary markers: None identified; the instructions do not specify delimiters or warnings for the agent to ignore instructions embedded in the API responses.
- Capability inventory: The skill can execute shell commands via the CLI and perform network operations through the Membrane proxy.
- Sanitization: There is no mention of sanitization, filtering, or validation of the data received from the external API before it is processed by the agent.
Audit Metadata