outfit
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the Membrane CLI (
@membranehq/cli) from the official npm registry. This is a vendor-provided utility tool used to facilitate communication between the agent and the Membrane orchestration platform. - [COMMAND_EXECUTION]: Executes shell commands via the
membraneCLI to manage user authentication, establish connections to the Outfit service, and run specific API actions. These operations are within the expected scope for an integration tool. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: Data ingested from the Outfit API through
membrane action runandmembrane requestcommands (found inSKILL.md). - Boundary markers: None explicitly defined in the skill instructions to separate external data from system instructions.
- Capability inventory: The skill has the capability to perform network requests and manipulate data within the connected Outfit account via CLI commands.
- Sanitization: The skill relies on the agent's default safety guardrails and Membrane's internal schema validation for actions.
Audit Metadata