sales-memberstack

Pass

Audited by Gen Agent Trust Hub on Jul 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a reference for Memberstack API integrations. No malicious behavior, obfuscation, or unauthorized access patterns were detected.
  • [DATA_EXFILTRATION]: The skill identifies the risks of client-side secret key exposure and correctly advises on secure storage using environment variables. All keys and IDs in examples use safe placeholders.
  • [PROMPT_INJECTION]: The skill describes processing external data via webhooks and JWTs. It provides guidance on mitigating indirect prompt injection risks by advising users to verify tokens server-side and re-fetch member data from the API. [Ingestion points: Webhook payloads and JWT tokens in references/platform-guide.md; Boundary markers: Instructions to handle null data and verify tokens; Capability inventory: HTTP requests via the requests library; Sanitization: Guidance provided for cryptographic verification and out-of-band validation.]
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 19, 2026, 04:16 PM
Security Audit — agent-trust-hub — sales-memberstack