regal
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill appropriately directs the agent to use the vendor's own CLI tool (@membranehq/cli) for all interactions. This method is preferred as it leverages the platform's built-in authentication and proxy capabilities, preventing the exposure of API keys or sensitive session data within the skill's instructions.
- [INDIRECT_PROMPT_INJECTION]: The skill interacts with the external Regal API, creating a surface for indirect prompt injection. 1. Ingestion points: Data ingested from Regal API actions and proxy requests described in SKILL.md. 2. Boundary markers: Absent; the skill does not define specific delimiters or instructions to ignore embedded content in API responses. 3. Capability inventory: Execution of CLI commands and network operations through the Membrane proxy. 4. Sanitization: Absent; the skill relies on the agent's core safety guardrails to process untrusted data.
Audit Metadata