pylon
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to install the '@membranehq/cli' package from the npm registry to enable interaction with the Membrane platform infrastructure.
- [COMMAND_EXECUTION]: Various 'membrane' CLI commands are utilized to perform authentication, connection management, and data operations within the Pylon environment.
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection via the processing of untrusted data returned by Pylon actions and search queries. * Ingestion points: Results from 'membrane action list', 'membrane action get', and 'membrane action run' commands (SKILL.md). * Boundary markers: No delimiters or warnings are used when interpolating external action data into the agent context. * Capability inventory: Extensive command execution capabilities via the 'membrane' CLI tool (SKILL.md). * Sanitization: No sanitization or escaping mechanisms are described for external data before it is processed by the agent.
Audit Metadata