grab

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Installs the @membranehq/cli package from the official NPM registry to enable platform interaction.
  • [COMMAND_EXECUTION]: Utilizes the membrane command-line tool to authenticate, connect to external services, and execute data management actions.
  • [PROMPT_INJECTION]: The skill accepts natural language input for searching and generating actions. Ingestion points: User-provided strings in the --intent and action create parameters within SKILL.md. Boundary markers: No explicit markers are used to isolate user input in the provided examples. Capability inventory: Shell command execution via the membrane binary for service interaction. Sanitization: None specified in the documentation, assuming enforcement by the CLI or backend service.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 12:08 PM