sap-successfactors
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the Membrane CLI via the command
npm install -g @membranehq/cli@latest. This downloads and installs software from the public NPM package registry. - [INDIRECT_PROMPT_INJECTION]: The skill processes data retrieved from SAP SuccessFactors, such as employee profiles, work experience, and goal records. This external content serves as a potential vector for indirect prompt injection.
- Ingestion points: Untrusted data enters the agent context through Membrane action outputs and proxy API requests (e.g.,
membrane action runandmembrane request). - Boundary markers: No explicit delimiters or instructions are provided to the agent to isolate or disregard potentially malicious instructions within the external data.
- Capability inventory: The skill facilitates network communication and API interaction with SAP SuccessFactors through the Membrane platform.
- Sanitization: The skill does not describe any sanitization or validation processes for the data ingested from the external HCM suite.
Audit Metadata