semaphoreci

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install the @membranehq/cli package from the official NPM registry to manage integration logic and authentication.- [COMMAND_EXECUTION]: Utilizes shell commands via the membrane CLI to connect accounts, search for actions, and automate workflows in Semaphore. These commands are standard for interacting with the Membrane ecosystem.- [PROMPT_INJECTION]: Processes natural language intents and descriptions to discover and create integration actions. While this introduces an ingestion surface for potential indirect prompt injection from CLI outputs, the risk is mitigated as these are core functional features of the vendor tool.- [CREDENTIALS_UNSAFE]: Explicitly advises against soliciting or hardcoding API keys, instead utilizing the platform's connection management to handle authentication and token refreshing securely server-side.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 10:53 PM