sapling

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the @membranehq/cli package from npm, which is the official command-line tool provided by the vendor (membranedev) for this integration.\n- [COMMAND_EXECUTION]: The skill instructs the agent to execute membrane CLI commands to perform authentication, discover available actions, and run API requests against the Sapling platform. These are standard operations for the skill's intended purpose.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from the Sapling HR platform, creating a potential surface for indirect prompt injection.\n
  • Ingestion points: External data is ingested through the output of the membrane action run and membrane request commands as described in SKILL.md.\n
  • Boundary markers: The instructions do not specify the use of delimiters or ignore-instructions to isolate data retrieved from the API.\n
  • Capability inventory: The skill includes the ability to perform network proxy requests and execute HR-related actions via the CLI.\n
  • Sanitization: There is no mention of explicit sanitization or validation of the data received from the Sapling API before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:25 AM
Security Audit — agent-trust-hub — sapling