square
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the
@membranehq/clipackage from the public npm registry. This package is an official tool provided by the vendor for managing integrations. - [COMMAND_EXECUTION]: The skill utilizes several CLI commands (
membrane login,membrane action run,membrane request) to interact with the Square API and manage authentication states. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data from Square (e.g., customer records, orders, and payment details). This introduces a surface for indirect prompt injection if the external data contains instructions intended to manipulate the agent's logic.
- Ingestion points: External data retrieved via
membrane action runand proxymembrane requestcalls. - Boundary markers: The skill body does not specify explicit delimiters or instructions for the agent to ignore embedded commands in the Square data.
- Capability inventory: The agent can perform network requests and execute actions through the Membrane CLI based on the processed data.
- Sanitization: There are no documented sanitization steps for the data retrieved from Square before it is presented to the agent context.
Audit Metadata