perfect-gym-solutions-sa

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the Membrane CLI (@membranehq/cli) from the official npm registry to facilitate the integration.\n- [COMMAND_EXECUTION]: The skill utilizes the membrane CLI tool to perform authentication (membrane login), manage connections (membrane connection ensure), and execute actions (membrane action run). These are authorized operations for the skill's purpose.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes data from the Perfect Gym Solutions S.A. API, which creates a surface for potential indirect prompt injection if the external data is malicious.\n
  • Ingestion points: Data enters the agent context through the outputs of membrane action run and membrane request CLI commands.\n
  • Boundary markers: There are no specific delimiters or instructions provided to the agent to treat the retrieved API data as untrusted or to ignore embedded instructions.\n
  • Capability inventory: The skill has the ability to execute CLI actions and make network requests via the Membrane proxy.\n
  • Sanitization: The skill does not implement explicit validation, filtering, or sanitization of the data returned from the Perfect Gym API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:25 PM
Security Audit — agent-trust-hub — perfect-gym-solutions-sa