signiflow
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the
@membranehq/clipackage via npm. This is a utility provided by the skill vendor for managing API connections. - [COMMAND_EXECUTION]: The agent is instructed to use shell commands (e.g.,
membrane login,membrane action run) to interact with the SigniFlow service and the Membrane platform. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the SigniFlow API, creating a surface for potential indirect prompt injection from external document data.
- Ingestion points: API outputs from actions and proxy requests in
SKILL.md. - Boundary markers: None provided in the integration instructions.
- Capability inventory: Shell command execution and network access via the
membraneCLI. - Sanitization: Not specified in the skill body.
Audit Metadata