square

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the @membranehq/cli package from the public npm registry. This package is an official tool provided by the vendor for managing integrations.
  • [COMMAND_EXECUTION]: The skill utilizes several CLI commands (membrane login, membrane action run, membrane request) to interact with the Square API and manage authentication states.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data from Square (e.g., customer records, orders, and payment details). This introduces a surface for indirect prompt injection if the external data contains instructions intended to manipulate the agent's logic.
  • Ingestion points: External data retrieved via membrane action run and proxy membrane request calls.
  • Boundary markers: The skill body does not specify explicit delimiters or instructions for the agent to ignore embedded commands in the Square data.
  • Capability inventory: The agent can perform network requests and execute actions through the Membrane CLI based on the processed data.
  • Sanitization: There are no documented sanitization steps for the data retrieved from Square before it is presented to the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 12:28 AM
Security Audit — agent-trust-hub — square