stockly

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the Membrane CLI package @membranehq/cli globally from the npm registry.
  • [COMMAND_EXECUTION]: The skill uses several commands involving the membrane CLI and npx to perform authentication, ensure connections, and execute actions or raw API requests.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data retrieved from the Stockly API, which represents an attack surface where untrusted data could influence agent behavior.
  • Ingestion points: Data is ingested via membrane action run and membrane request commands as described in SKILL.md.
  • Boundary markers: The instructions do not specify any delimiters or safety markers to differentiate between instructions and external data.
  • Capability inventory: The skill possesses the ability to install packages, manage network connections, and perform authenticated HTTP requests.
  • Sanitization: There are no documented sanitization or validation steps for the data received from the external API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 07:23 AM
Security Audit — agent-trust-hub — stockly