kintone

Pass

Audited by Gen Agent Trust Hub on Apr 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is subject to indirect prompt injection risks due to processing data from Kintone. * Ingestion points: Untrusted data enters the agent context through the get-records and get-record-comments actions defined in SKILL.md. * Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat retrieved Kintone content as untrusted. * Capability inventory: The skill allows the agent to create, update, or delete data via the membrane action run and membrane request commands as specified in SKILL.md. * Sanitization: No validation or sanitization mechanisms for the retrieved Kintone data are mentioned.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli NPM package. As this is an official tool from the skill's author, it is a standard dependency for this integration.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 23, 2026, 09:08 AM