optimoroute

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package from the public NPM registry. This is the official tool used to interact with the author's (membranedev) platform.
  • [COMMAND_EXECUTION]: Shell commands using the membrane CLI are used to manage authentication, search for connectors, and execute actions against the OptimoRoute API.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it processes external data from the OptimoRoute API. 1. Ingestion points: API responses from membrane action run and membrane request. 2. Boundary markers: No specific delimiters or boundary markers are defined to isolate external data from instructions. 3. Capability inventory: The skill utilizes shell command execution via the Membrane CLI. 4. Sanitization: No explicit sanitization or filtering of the external data is documented in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 01:46 PM