octopus-deploy

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the Membrane CLI (@membranehq/cli) globally via npm and uses npx to execute it. These are official tools provided by the vendor to facilitate the integration.
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with external data from the Octopus Deploy API, creating a potential surface for indirect prompt injection.
    • Ingestion points: External data enters the agent's context through commands like membrane action list, membrane action run, and membrane request which fetch information from Octopus Deploy environments, projects, and tasks.
    • Boundary markers: The instructions do not define specific delimiters or instructions for the agent to ignore potentially malicious content embedded within the API responses.
    • Capability inventory: The agent has the ability to perform actions (membrane action run) and send arbitrary requests (membrane request) to the Octopus Deploy API, which could be exploited if the agent follows instructions found in the retrieved data.
    • Sanitization: There are no explicit sanitization or validation routines described for the data returned from the external API before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 04:08 PM
Security Audit — agent-trust-hub — octopus-deploy