expertai
Pass
Audited by Gen Agent Trust Hub on Apr 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@membranehq/clitool from the npm registry. This is an official utility provided by the vendor to manage the integration. - [COMMAND_EXECUTION]: The skill utilizes the
membranecommand-line utility to manage connections and execute actions within the Expert.ai environment. - [DATA_EXFILTRATION]: Facilitates communication with the Expert.ai API through a proxy service for the purpose of data management and workflow automation.
- [PROMPT_INJECTION]: The skill ingests data from Expert.ai API responses and possesses capabilities such as
membrane action runandmembrane request. While it lacks explicit boundary markers or sanitization for this external content, this is a standard characteristic of data-processing integrations.
Audit Metadata