platform9

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Installs the official Membrane CLI (@membranehq/cli) from the npm registry to enable interaction with the platform.
  • [COMMAND_EXECUTION]: Instructs the agent to execute shell commands using the membrane CLI for authentication, connection management, and action execution.
  • [REMOTE_CODE_EXECUTION]: Features the ability to dynamically create and build actions based on natural language descriptions (membrane action create), which is a core functionality of the Membrane integration platform.
  • [DATA_EXFILTRATION]: Provides management capabilities for sensitive infrastructure data, including clusters, secrets, and keys within the Platform9 environment, consistent with its role as a management plane tool.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface. Evidence: 1. Ingestion points: Platform9 data and action outputs are ingested into the agent context via SKILL.md instructions. 2. Boundary markers: Absent. 3. Capability inventory: Command execution via CLI and dynamic action creation. 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 10:28 PM
Security Audit — agent-trust-hub — platform9