minio

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Installs the @membranehq/cli Node.js package from the official registry. This is a vendor-owned resource for the Membrane platform.
  • [COMMAND_EXECUTION]: Uses the membrane command-line tool to perform various operations including user authentication (membrane login), connection management (membrane connect, membrane connection list), and data operations (membrane action run, membrane request).
  • [PROMPT_INJECTION]: Potential surface for indirect prompt injection exists when the agent processes object data or metadata retrieved from MinIO buckets.
  • Ingestion points: Data retrieved via membrane action run or membrane request commands.
  • Boundary markers: Not implemented.
  • Capability inventory: File system access (via CLI), network operations (via CLI), and shell command execution.
  • Sanitization: No explicit sanitization or validation of external data is specified in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 09:50 AM