sales-memberful

Pass

Audited by Gen Agent Trust Hub on Jul 19, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No safety bypass or instructions to ignore constraints were detected.
  • [DATA_EXFILTRATION]: The skill uses placeholders and environment variables for sensitive authentication data like API keys and webhook secrets, avoiding hardcoded credentials.
  • [COMMAND_EXECUTION]: The skill includes a command to add a related skill using the platform's installation tool (npx skills add). This is a legitimate use for connecting a suite of tools from the same author.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to handle external data from webhooks and APIs. It mitigates risk by providing patterns for cryptographic signature verification (HMAC-SHA256) and recommending that the agent re-verifies state from the source of truth.
  • [EXTERNAL_DOWNLOADS]: References are limited to Memberful's official repository and documentation, which are trusted sources for this integration.
  • [REMOTE_CODE_EXECUTION]: No remote code execution or untrusted dependency installation patterns were detected. The Python recipes provided use common, verified libraries.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 19, 2026, 04:16 PM
Security Audit — agent-trust-hub — sales-memberful