opencage

Warn

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: MEDIUMMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [METADATA_POISONING]: The skill's YAML frontmatter contains a description that claims functionality for managing CRM-related entities such as "Persons, Organizations, Deals, Leads, Projects, Activities." However, the actual implementation and body of the skill are dedicated entirely to the OpenCage geocoding service. This discrepancy between metadata and actual functionality is deceptive.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes geographic data and place names from the external OpenCage API, which is a potential vector for indirect instructions.
  • Ingestion points: Data is received from the external OpenCage API via membrane action run and membrane request calls.
  • Boundary markers: The instructions do not define delimiters or specific "ignore" rules for data returned from the API.
  • Capability inventory: The skill has the ability to execute network requests to the OpenCage API and run local terminal commands using the Membrane CLI.
  • Sanitization: There is no mention of validation or filtering for the external content before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill requires running the membrane command-line interface to manage authentication, poll connections, and execute API actions.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package globally via NPM. As this package is the official interface for the skill vendor's platform, it is documented as a standard setup requirement.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 28, 2026, 04:43 PM
Security Audit — agent-trust-hub — opencage