novu
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@membranehq/clipackage from the NPM registry. This is the official command-line interface provided by the skill's vendor to facilitate integration. - [COMMAND_EXECUTION]: The skill requires the agent to execute various shell commands using the
membraneCLI. These commands handle sensitive operations including authentication (membrane login), connection management (membrane connection ensure), and direct API interaction (membrane action runandmembrane request). - [INDIRECT_PROMPT_INJECTION]: The skill describes a connection polling process where the agent reads a
clientAction.agentInstructionsfield. This field is explicitly designed to provide programmatic instructions to the AI agent from an external source (the Membrane API). - Ingestion points: Output of
membrane connection getas described inSKILL.md. - Boundary markers: None identified; the instructions are intended for programmatic consumption by the agent.
- Capability inventory: The skill possesses shell execution capabilities through the Membrane CLI, including the ability to perform network requests and run arbitrary actions.
- Sanitization: None mentioned; the agent is instructed to follow the provided instructions to proceed with the setup.
Audit Metadata