squarespace

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the Membrane CLI tool (@membranehq/cli) from the npm registry. This is a standard procedure for utilizing the vendor's platform capabilities.
  • [COMMAND_EXECUTION]: The skill instructions involve executing membrane CLI commands to manage user sessions, establish authenticated connections to Squarespace, and perform API operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from Squarespace, which presents a surface for indirect prompt injection if external data were to contain instructions intended for the agent. * Ingestion points: Data retrieved from Squarespace via API actions (SKILL.md). * Boundary markers: None present. * Capability inventory: Network requests and site management via the membrane CLI (SKILL.md). * Sanitization: None present.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 12:16 AM
Security Audit — agent-trust-hub — squarespace