novu

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package from the NPM registry. This is the official command-line interface provided by the skill's vendor to facilitate integration.
  • [COMMAND_EXECUTION]: The skill requires the agent to execute various shell commands using the membrane CLI. These commands handle sensitive operations including authentication (membrane login), connection management (membrane connection ensure), and direct API interaction (membrane action run and membrane request).
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a connection polling process where the agent reads a clientAction.agentInstructions field. This field is explicitly designed to provide programmatic instructions to the AI agent from an external source (the Membrane API).
  • Ingestion points: Output of membrane connection get as described in SKILL.md.
  • Boundary markers: None identified; the instructions are intended for programmatic consumption by the agent.
  • Capability inventory: The skill possesses shell execution capabilities through the Membrane CLI, including the ability to perform network requests and run arbitrary actions.
  • Sanitization: None mentioned; the agent is instructed to follow the provided instructions to proceed with the setup.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 11:27 PM
Security Audit — agent-trust-hub — novu