traceable
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill utilizes the official Membrane CLI (
@membranehq/cli) to facilitate integration with the Traceable API. This is a standard and recommended practice for the vendor's ecosystem, ensuring that authentication and network requests are handled through a centralized, managed tool. - [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection by ingesting data from external Traceable API responses which are then processed by the agent.
- Ingestion points: Data enters the agent context through the terminal output of
membrane action runandmembrane requestcommands. - Boundary markers: No specific delimiters or "ignore instructions" warnings are defined in the instructions for handling the API output.
- Capability inventory: The skill possesses the ability to execute shell commands via the
membraneCLI, which includes performing authenticated network requests and executing predefined actions. - Sanitization: There is no documented validation or sanitization of the data returned from the Traceable API before it is consumed by the agent.
Audit Metadata