Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the vendor-provided command-line tool
@membranehq/clifrom the npm registry. - [COMMAND_EXECUTION]: The skill uses the
membraneCLI for managing connections and executing WhatsApp actions via shell commands. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from WhatsApp messages and profiles, which are untrusted external sources.
- Ingestion points: WhatsApp API data retrieved through Membrane actions.
- Boundary markers: No delimiters or safety instructions are defined for the agent when handling this data.
- Capability inventory: The skill can send messages and make arbitrary API requests via the Membrane proxy.
- Sanitization: No sanitization of external content is specified.
Audit Metadata