outfit

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the Membrane CLI (@membranehq/cli) from the official npm registry. This is a vendor-provided utility tool used to facilitate communication between the agent and the Membrane orchestration platform.
  • [COMMAND_EXECUTION]: Executes shell commands via the membrane CLI to manage user authentication, establish connections to the Outfit service, and run specific API actions. These operations are within the expected scope for an integration tool.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: Data ingested from the Outfit API through membrane action run and membrane request commands (found in SKILL.md).
  • Boundary markers: None explicitly defined in the skill instructions to separate external data from system instructions.
  • Capability inventory: The skill has the capability to perform network requests and manipulate data within the connected Outfit account via CLI commands.
  • Sanitization: The skill relies on the agent's default safety guardrails and Membrane's internal schema validation for actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 08:41 AM
Security Audit — agent-trust-hub — outfit