traceable

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill utilizes the official Membrane CLI (@membranehq/cli) to facilitate integration with the Traceable API. This is a standard and recommended practice for the vendor's ecosystem, ensuring that authentication and network requests are handled through a centralized, managed tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection by ingesting data from external Traceable API responses which are then processed by the agent.
  • Ingestion points: Data enters the agent context through the terminal output of membrane action run and membrane request commands.
  • Boundary markers: No specific delimiters or "ignore instructions" warnings are defined in the instructions for handling the API output.
  • Capability inventory: The skill possesses the ability to execute shell commands via the membrane CLI, which includes performing authenticated network requests and executing predefined actions.
  • Sanitization: There is no documented validation or sanitization of the data returned from the Traceable API before it is consumed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:10 PM
Security Audit — agent-trust-hub — traceable