radar

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The instructions include the installation of the @membranehq/cli package from the NPM registry. This tool is a resource provided by the vendor to facilitate secure communication with the Radar API.
  • [COMMAND_EXECUTION]: The skill relies on executing various membrane CLI commands to manage authentication, discover available Radar actions, and execute API requests. These commands are standard for the skill's intended administrative and integration purposes.
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with external data from the Radar API, which acts as a potential surface for indirect prompt injection if the ingested data contains malicious instructions.
  • Ingestion points: Data enters the agent's context through the output of commands like membrane action run and membrane request.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded content within the Radar data.
  • Capability inventory: The skill provides the agent with the ability to execute shell commands via the membrane CLI and perform network operations through the Membrane proxy.
  • Sanitization: There are no explicit validation or sanitization steps defined for the external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 01:22 PM
Security Audit — agent-trust-hub — radar