quickbooks
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
@membranehq/clipackage from the Node Package Manager (npm) to provide the necessary tooling for Quickbooks interaction. - [COMMAND_EXECUTION]: The skill relies on shell commands to manage authentication, establish connections, and execute actions within the Quickbooks environment via the
membranecommand-line utility. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Quickbooks entities, which could contain instructions intended to influence the agent's behavior.
- Ingestion points: Data enters the agent's context through output from the
membrane action runandmembrane requestcommands (found inSKILL.md). - Boundary markers: The instructions do not define specific delimiters or instructions to treat the retrieved accounting data as untrusted content.
- Capability inventory: The skill allows the agent to read and write sensitive accounting records and perform arbitrary HTTP requests to the Quickbooks API through a proxy.
- Sanitization: No explicit validation or filtering is mentioned for the data returned from QuickBooks before it is parsed by the agent.
Audit Metadata