formidable-forms

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface Detection:\n
  • Ingestion points: Untrusted data is retrieved via list-entries, get-entry, list-form-fields, list-forms, and get-form commands specified in SKILL.md.\n
  • Boundary markers: The skill does not define specific delimiters or warnings to isolate processed data from agent instructions.\n
  • Capability inventory: The skill possesses capabilities to modify data through actions like delete-entry, update-entry, and create-form, as well as raw API access via membrane request.\n
  • Sanitization: There are no documented procedures for sanitizing or validating external input before it is used by the agent.\n- [EXTERNAL_DOWNLOADS]: The skill prompts the installation of the @membranehq/cli NPM package. This is a standard dependency from the primary vendor to support the skill's functionality.\n- [COMMAND_EXECUTION]: The skill utilizes the membrane CLI for managing service connections and executing API-wrapped actions, which is the intended use case for this integration.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 11:15 PM