pendo
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill guides the user to install the
@membranehq/clipackage from the NPM registry. This is a vendor-owned resource necessary for the integration. - [COMMAND_EXECUTION]: Utilizes the
membranecommand-line tool to perform authentication, manage app connections, and execute actions against the Pendo API. These commands are standard for the skill's stated purpose and operate within the vendor's ecosystem. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Pendo (such as guides, feedback, and segments), which creates a theoretical surface for indirect prompt injection.
- Ingestion points: External data is retrieved via the
membrane action runandmembrane requestcommands (SKILL.md). - Boundary markers: No explicit data delimiters are defined in the instructions.
- Capability inventory: The skill uses the
membraneCLI for network communication and data management. - Sanitization: The skill relies on the Membrane platform's internal handling and proxying to manage API data safely.
Audit Metadata