schedule-it
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the Membrane CLI tool (
@membranehq/cli@latest) via the NPM package manager. This tool is a vendor-provided dependency used to manage authentication and interact with the Membrane platform. - [COMMAND_EXECUTION]: The skill relies on the execution of
membraneCLI commands (such asmembrane login,membrane action, andmembrane request) to perform its primary functions, involving network operations and local terminal interaction. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from the external Schedule it API, which could potentially contain instructions aimed at influencing the agent's behavior.
- Ingestion points: Untrusted data enters the context through the output of commands like
membrane action runandmembrane requestas described inSKILL.md. - Boundary markers: The skill does not define specific delimiters or "ignore embedded instructions" warnings for the data retrieved from the API.
- Capability inventory: The skill has the capability to execute shell commands via the CLI, perform authenticated network requests, and modify remote resources.
- Sanitization: There is no documentation of sanitization, filtering, or validation of the content returned by the external API before it is processed by the agent.
Audit Metadata