opencage

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli tool from the npm registry. This is an official resource provided by the author to facilitate the integration.\n- [COMMAND_EXECUTION]: The instructions direct the agent to execute shell commands using the membrane utility for service connectivity and geocoding operations.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface. Ingestion points: User-supplied or external strings used in the --intent and --description arguments of CLI commands. Boundary markers: None are present in the provided command templates. Capability inventory: Subprocess execution of the membrane CLI which can run and create actions. Sanitization: No validation or escaping of interpolated strings is described.\n- [PROMPT_INJECTION]: The metadata in the skill's YAML frontmatter incorrectly describes CRM-related features (Persons, Deals, Leads) which are not part of the OpenCage geocoding service. This documentation error does not pose a direct security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 04:52 PM