privyr

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the @membranehq/cli package globally via npm. This is a standard utility provided by the vendor for managing integrations and authentication.
  • [COMMAND_EXECUTION]: The instructions involve executing various shell commands via the membrane CLI, such as membrane login, membrane connection ensure, and membrane action run. These commands are used to manage the lifecycle of the integration and perform data operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from the external Privyr API.
  • Ingestion points: Data retrieved from Privyr via membrane action run or direct proxy requests (membrane request) enters the agent's context in SKILL.md.
  • Boundary markers: The skill does not provide specific instructions or delimiters to help the agent distinguish between data and instructions when processing record content.
  • Capability inventory: The skill possesses capabilities for network interaction and data modification through the Membrane CLI tools across all described actions.
  • Sanitization: No explicit sanitization or validation logic is described for the content returned from the external API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:25 PM
Security Audit — agent-trust-hub — privyr