regal

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill appropriately directs the agent to use the vendor's own CLI tool (@membranehq/cli) for all interactions. This method is preferred as it leverages the platform's built-in authentication and proxy capabilities, preventing the exposure of API keys or sensitive session data within the skill's instructions.
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with the external Regal API, creating a surface for indirect prompt injection. 1. Ingestion points: Data ingested from Regal API actions and proxy requests described in SKILL.md. 2. Boundary markers: Absent; the skill does not define specific delimiters or instructions to ignore embedded content in API responses. 3. Capability inventory: Execution of CLI commands and network operations through the Membrane proxy. 4. Sanitization: Absent; the skill relies on the agent's core safety guardrails to process untrusted data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:59 AM
Security Audit — agent-trust-hub — regal