watchman-monitoring

Pass

Audited by Gen Agent Trust Hub on May 5, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the @membranehq/cli package from the official npm registry to enable interaction with the Membrane platform.
  • [COMMAND_EXECUTION]: Utilizes membrane CLI commands to perform monitoring tasks, manage server connections, and execute actions within the vendor's ecosystem.
  • [CREDENTIALS_UNSAFE]: Includes explicit instructions to avoid requesting or managing user secrets directly, instead leveraging the platform's automated credential handling.
  • [PROMPT_INJECTION]: Identifies an ingestion surface for external data via tool outputs, which is a potential vector for indirect instructions. Ingestion points: Data is received from the output of membrane action run commands as described in SKILL.md. Boundary markers: None identified in the provided instructions. Capability inventory: Includes commands for authentication, connection management, and running/creating actions (SKILL.md). Sanitization: No specific sanitization or validation logic is detailed for the processed output.
Audit Metadata
Risk Level
SAFE
Analyzed
May 5, 2026, 05:18 PM