reward-sciences
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to ingest and process untrusted data from external API endpoints while possessing network-enabled tool capabilities.\n
- Ingestion points: Data is fetched from Reward Sciences via the
membrane action runandmembrane requestcommands.\n - Boundary markers: There are no instructions for the agent to use specific delimiters or to ignore potential instructions embedded within the retrieved external content.\n
- Capability inventory: The skill provides access to the Membrane CLI, allowing for authenticated network communication and data manipulation.\n
- Sanitization: No specific mechanisms for sanitizing or validating API responses are mentioned before the data is integrated into the agent's context.\n- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the vendor's command-line interface to facilitate interactions with the platform.\n
- Evidence: The documentation instructs the user to run
npm install -g @membranehq/cli@latestto set up the necessary environment.
Audit Metadata