sap-ariba
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill directs the agent to execute shell commands for installing the Membrane CLI and managing integration workflows.
- [EXTERNAL_DOWNLOADS]: Fetches the official
@membranehq/clipackage from the public npm registry, which is the tool required for the skill's functionality. - [PROMPT_INJECTION]: The skill defines a surface for processing untrusted data by interpolating user-provided intent and descriptions into CLI commands. Ingestion points:
intentandDESCRIPTIONfields inSKILL.md. Boundary markers: Absent. Capability inventory: CLI command execution includingaction listandaction createinSKILL.md. Sanitization: Not specified.
Audit Metadata