plivo

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches and installs the official @membranehq/cli tool from the npm registry to manage communication with the Plivo platform.
  • [COMMAND_EXECUTION]: Employs shell commands via the Membrane CLI to authenticate the user and perform programmatic actions against the Plivo API, such as initiating calls or sending messages.
  • [INDIRECT_PROMPT_INJECTION]: Ingests and processes potentially untrusted data from the Plivo API, such as SMS message content or call records, which could contain adversarial instructions. Ingestion points: Data is received from the membrane action run and membrane request commands. Boundary markers: None identified in the provided instructions. Capability inventory: Includes network access to Plivo and Membrane services via the CLI. Sanitization: No specific sanitization or escaping mechanisms for API responses are detailed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 11:56 AM
Security Audit — agent-trust-hub — plivo