checking-member-access
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is designed for read-only diagnostics and explanation of access control settings. It explicitly prohibits the agent from attempting to change rules, stating that read tools cannot write.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external tools such as
posthog:access-control-members-listandposthog:roles-list. This constitutes an attack surface where instructions could be embedded in metadata like role names or object titles. However, the skill's capabilities are limited to generating descriptive text and it does not possess dangerous tools for command execution, file writing, or network exfiltration to non-vendor domains. - [SAFE]: All referenced tools (
posthog:*) and URLs (posthog.com) belong to the verified vendor for this skill. Network references are limited to official documentation and plan comparison pages.
Audit Metadata