world-news-api

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli Node.js package. This is the official command-line interface for the Membrane platform as indicated by the vendor context and homepage.- [COMMAND_EXECUTION]: The instructions involve running several membrane CLI commands to manage authentication (membrane login), connection management (membrane connect, membrane connection list), and API interaction (membrane action run, membrane request). These are standard operational commands for the described service.- [PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection by processing content from the World News API.
  • Ingestion points: The skill processes data from API responses via membrane action run and membrane request commands.
  • Boundary markers: No specific delimiters or instructions to ignore embedded content are provided for the API data.
  • Capability inventory: The skill utilizes shell command execution via the membrane CLI.
  • Sanitization: No sanitization or validation of the external API content is performed before it is presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 09:11 AM