sellercloud

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs the user to install the @membranehq/cli package from the npm registry, which is the official tool provided by the platform vendor.
  • [COMMAND_EXECUTION]: The agent is instructed to use the membrane CLI for authentication, connection setup, and running Sellercloud actions.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from Sellercloud (e.g., product details, order notes), creating a surface for potential instructions to be embedded in external data.
  • Ingestion points: Data retrieved through membrane action run and membrane request commands.
  • Boundary markers: No explicit delimiters are provided in the prompts to differentiate between instructions and external data.
  • Capability inventory: The skill has the capability to read and write data to the Sellercloud API via the Membrane proxy.
  • Sanitization: There is no mention of sanitizing or filtering the content received from the external API before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 04:15 PM
Security Audit — agent-trust-hub — sellercloud