stockly
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the Membrane CLI package
@membranehq/cliglobally from the npm registry. - [COMMAND_EXECUTION]: The skill uses several commands involving the
membraneCLI andnpxto perform authentication, ensure connections, and execute actions or raw API requests. - [INDIRECT_PROMPT_INJECTION]: The skill processes data retrieved from the Stockly API, which represents an attack surface where untrusted data could influence agent behavior.
- Ingestion points: Data is ingested via
membrane action runandmembrane requestcommands as described inSKILL.md. - Boundary markers: The instructions do not specify any delimiters or safety markers to differentiate between instructions and external data.
- Capability inventory: The skill possesses the ability to install packages, manage network connections, and perform authenticated HTTP requests.
- Sanitization: There are no documented sanitization or validation steps for the data received from the external API.
Audit Metadata