schedule-it

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the Membrane CLI tool (@membranehq/cli@latest) via the NPM package manager. This tool is a vendor-provided dependency used to manage authentication and interact with the Membrane platform.
  • [COMMAND_EXECUTION]: The skill relies on the execution of membrane CLI commands (such as membrane login, membrane action, and membrane request) to perform its primary functions, involving network operations and local terminal interaction.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from the external Schedule it API, which could potentially contain instructions aimed at influencing the agent's behavior.
  • Ingestion points: Untrusted data enters the context through the output of commands like membrane action run and membrane request as described in SKILL.md.
  • Boundary markers: The skill does not define specific delimiters or "ignore embedded instructions" warnings for the data retrieved from the API.
  • Capability inventory: The skill has the capability to execute shell commands via the CLI, perform authenticated network requests, and modify remote resources.
  • Sanitization: There is no documentation of sanitization, filtering, or validation of the content returned by the external API before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:44 AM
Security Audit — agent-trust-hub — schedule-it