confluence

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the @membranehq/cli package via npm to facilitate interaction with Confluence through the Membrane platform.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it retrieves and processes untrusted data from external Confluence pages, blog posts, and comments.
  • Ingestion points: Found in SKILL.md via actions such as list-pages, get-page, list-blog-posts, get-blog-post, and list-page-comments.
  • Boundary markers: The instructions do not define specific delimiters or warnings for the agent to ignore embedded instructions in the retrieved content.
  • Capability inventory: The skill can execute network requests via the membrane CLI and write data back to Confluence using actions like create-page, update-page, and create-page-comment.
  • Sanitization: There is no evidence of content sanitization or validation for the data ingested from Confluence.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:26 AM
Security Audit — agent-trust-hub — confluence