shortcut

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the @membranehq/cli Node.js package from the official npm registry. This CLI tool is a vendor-provided resource used to facilitate authentication and execute Shortcut integration actions safely through the Membrane platform.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from Shortcut (e.g., stories, epics, and workspace members), which creates a surface for potential indirect prompt injection if external data sources contain malicious instructions.
  • Ingestion points: Shortcut records are retrieved via membrane action run and membrane request calls defined in SKILL.md.
  • Boundary markers: There are no explicit delimiters or specific prompt instructions defined to isolate the ingested Shortcut data from the agent's operational instructions.
  • Capability inventory: The skill is capable of performing network operations and local CLI commands via the Membrane harness to manage workspace records and configurations.
  • Sanitization: No explicit content sanitization or validation methods are described for the text data returned from Shortcut endpoints.
  • [COMMAND_EXECUTION]: The skill documentation includes several commands for the Membrane CLI (membrane login, membrane connection, membrane action) which are used to authenticate the user and interact with the Shortcut API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 05:24 PM
Security Audit — agent-trust-hub — shortcut