mackerel

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs users to install @membranehq/cli from the npm registry, which is the legitimate management tool for the Membrane ecosystem.
  • [COMMAND_EXECUTION]: It uses membrane CLI commands to interact with service connections and execute actions, scoped to monitoring and automation tasks.
  • [PROMPT_INJECTION]: The skill processes external data from Mackerel, creating a surface for indirect prompt injection. Ingestion points: Data is fetched via membrane action run and membrane request. Boundary markers: None. Capability inventory: Subprocess execution and network requests through the membrane CLI. Sanitization: None.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 04:28 PM