scrapeninja
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads and installs the
@membranehq/clipackage from the official npm registry to facilitate communication with ScrapeNinja. - [COMMAND_EXECUTION]: The skill executes various
membraneCLI commands to manage authentication tokens, create connections, and run scraping actions. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to the way it handles user input during action discovery.
- Ingestion points: User-supplied queries are ingested and passed directly to the
membrane action list --intentcommand as documented inSKILL.md. - Boundary markers: No explicit delimiters or boundary markers are instructed for use with the user-provided query strings.
- Capability inventory: The skill possesses the capability to execute shell commands, perform authenticated network requests via
membrane request, and write/read data through ScrapeNinja actions. - Sanitization: The instructions do not define sanitization or validation logic for the input strings before they are interpolated into shell commands.
Audit Metadata