quipu

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package globally via npm to provide the necessary tooling for the integration.
  • [COMMAND_EXECUTION]: The skill relies on the execution of membrane CLI commands to handle user authentication, establish connections to the Quipu service, and run specific financial management actions.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from the Quipu platform, which serves as a potential surface for indirect prompt injection vulnerabilities.
  • Ingestion points: Data is ingested through API responses returned by membrane action run and membrane request commands as described in SKILL.md.
  • Boundary markers: The skill does not define specific delimiters or instructions to the agent to disregard instructions that may be embedded in the retrieved financial data.
  • Capability inventory: The skill utilizes the membrane CLI to perform network requests and data actions, providing the functional capability that could be targeted by an injection.
  • Sanitization: No evidence of data sanitization, filtering, or validation is present to mitigate the risks associated with processing external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 06:34 PM
Security Audit — agent-trust-hub — quipu