payrexx
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@membranehq/clipackage from the NPM registry. This is a scoped package originating from the skill author's organization. - [COMMAND_EXECUTION]: The skill relies on the
membranecommand-line interface to perform authentication, manage payment connections, and execute API actions. These commands interact with the local environment and network to facilitate the Payrexx integration. - [INDIRECT_PROMPT_INJECTION]: The skill processes data retrieved from the Payrexx API, creating a surface for potential indirect prompt injection attacks where instructions could be embedded in payment records or user data.
- Ingestion points: Data enters the agent's context through the output of
membrane action runandmembrane requestcommands in theSKILL.mdfile. - Boundary markers: The provided instructions do not specify any delimiters or safety markers to isolate external API data from the agent's core instructions.
- Capability inventory: The skill possesses the capability to execute shell commands via the CLI, write to the filesystem, and perform network requests through the Membrane proxy.
- Sanitization: There is no evidence of explicit sanitization, filtering, or validation logic applied to the data fetched from Payrexx before the agent processes it.
Audit Metadata