servicenow

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli package via npm to facilitate communication with the ServiceNow API. This is a vendor-provided tool required for the skill's functionality.
  • [COMMAND_EXECUTION]: The skill uses the membrane CLI to perform operations such as login, connection management, action discovery, and API requests.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from ServiceNow (e.g., incidents, tasks, articles) which may contain content from untrusted external users. 1. Ingestion points: Data enters the agent context through membrane action run and membrane request commands in SKILL.md. 2. Boundary markers: The instructions in SKILL.md do not specify any delimiters or warnings to ignore instructions embedded in the retrieved data. 3. Capability inventory: The skill utilizes shell command execution and network operations via the Membrane CLI as described in SKILL.md. 4. Sanitization: No specific filtering or sanitization steps are documented for the incoming ServiceNow data in SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:31 AM
Security Audit — agent-trust-hub — servicenow