shortcut
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the
@membranehq/cliNode.js package from the official npm registry. This CLI tool is a vendor-provided resource used to facilitate authentication and execute Shortcut integration actions safely through the Membrane platform. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from Shortcut (e.g., stories, epics, and workspace members), which creates a surface for potential indirect prompt injection if external data sources contain malicious instructions.
- Ingestion points: Shortcut records are retrieved via
membrane action runandmembrane requestcalls defined in SKILL.md. - Boundary markers: There are no explicit delimiters or specific prompt instructions defined to isolate the ingested Shortcut data from the agent's operational instructions.
- Capability inventory: The skill is capable of performing network operations and local CLI commands via the Membrane harness to manage workspace records and configurations.
- Sanitization: No explicit content sanitization or validation methods are described for the text data returned from Shortcut endpoints.
- [COMMAND_EXECUTION]: The skill documentation includes several commands for the Membrane CLI (
membrane login,membrane connection,membrane action) which are used to authenticate the user and interact with the Shortcut API.
Audit Metadata