sap-ariba

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to execute shell commands for installing the Membrane CLI and managing integration workflows.
  • [EXTERNAL_DOWNLOADS]: Fetches the official @membranehq/cli package from the public npm registry, which is the tool required for the skill's functionality.
  • [PROMPT_INJECTION]: The skill defines a surface for processing untrusted data by interpolating user-provided intent and descriptions into CLI commands. Ingestion points: intent and DESCRIPTION fields in SKILL.md. Boundary markers: Absent. Capability inventory: CLI command execution including action list and action create in SKILL.md. Sanitization: Not specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 01:00 AM