reward-sciences

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to ingest and process untrusted data from external API endpoints while possessing network-enabled tool capabilities.\n
  • Ingestion points: Data is fetched from Reward Sciences via the membrane action run and membrane request commands.\n
  • Boundary markers: There are no instructions for the agent to use specific delimiters or to ignore potential instructions embedded within the retrieved external content.\n
  • Capability inventory: The skill provides access to the Membrane CLI, allowing for authenticated network communication and data manipulation.\n
  • Sanitization: No specific mechanisms for sanitizing or validating API responses are mentioned before the data is integrated into the agent's context.\n- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the vendor's command-line interface to facilitate interactions with the platform.\n
  • Evidence: The documentation instructs the user to run npm install -g @membranehq/cli@latest to set up the necessary environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 06:32 AM
Security Audit — agent-trust-hub — reward-sciences