samsara

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to install the @membranehq/cli package from the NPM registry, which is a core component provided by the vendor for managing integrations.
  • [COMMAND_EXECUTION]: The skill relies on executing membrane CLI commands to interact with the Samsara API and manage connections.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from the external Samsara API, creating an attack surface for indirect prompt injection. 1. Ingestion points: External data enters the agent context through the output of membrane action run and membrane request commands in SKILL.md. 2. Boundary markers: There are no explicit delimiters or instructions provided to the agent to distinguish between its own logic and potentially untrusted data from the API. 3. Capability inventory: The skill possesses capabilities to execute API actions and perform network requests via the membrane CLI as seen in SKILL.md. 4. Sanitization: No data sanitization or validation logic is specified for the API responses before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:36 PM
Security Audit — agent-trust-hub — samsara