watchman-monitoring
Pass
Audited by Gen Agent Trust Hub on May 5, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the
@membranehq/clipackage from the official npm registry to enable interaction with the Membrane platform. - [COMMAND_EXECUTION]: Utilizes
membraneCLI commands to perform monitoring tasks, manage server connections, and execute actions within the vendor's ecosystem. - [CREDENTIALS_UNSAFE]: Includes explicit instructions to avoid requesting or managing user secrets directly, instead leveraging the platform's automated credential handling.
- [PROMPT_INJECTION]: Identifies an ingestion surface for external data via tool outputs, which is a potential vector for indirect instructions. Ingestion points: Data is received from the output of
membrane action runcommands as described in SKILL.md. Boundary markers: None identified in the provided instructions. Capability inventory: Includes commands for authentication, connection management, and running/creating actions (SKILL.md). Sanitization: No specific sanitization or validation logic is detailed for the processed output.
Audit Metadata