rocketreach

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the @membranehq/cli utility from the NPM registry to manage RocketReach interactions.
  • [COMMAND_EXECUTION]: Instructions include the use of terminal commands to authenticate the user and execute API actions through the Membrane framework.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a conduit for data from RocketReach, which involves processing externally sourced professional and company information. This constitutes a standard injection surface common to data retrieval skills.
  • Ingestion points: Data retrieved from RocketReach endpoints via membrane action run or membrane request (SKILL.md).
  • Boundary markers: The skill does not define specific prompt delimiters for external content.
  • Capability inventory: Network requests to RocketReach API and local CLI execution for configuration management.
  • Sanitization: Standard handling by the underlying Membrane platform is assumed, though not explicitly detailed in the skill markdown.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 07:09 AM
Security Audit — agent-trust-hub — rocketreach