vero

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the '@membranehq/cli' package from the npm registry, which is a verified and expected dependency for interacting with the Membrane platform.\n- [COMMAND_EXECUTION]: Membrane CLI commands are utilized to manage authentication, list connections, and execute actions; these are legitimate operations necessary for the skill's primary purpose and do not represent arbitrary command execution.\n- [PROMPT_INJECTION]: A surface for indirect prompt injection exists where the skill ingests data from Vero API responses and processes natural language intents (SKILL.md). Capability inventory is restricted to authorized actions via the CLI, and the skill relies on the vendor platform for sanitization. No malicious patterns or bypass attempts were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 11:41 AM