oracle-eloqua

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package from the official NPM registry. This is a vendor-owned tool used to interact with the Membrane platform.
  • [COMMAND_EXECUTION]: The skill uses various membrane CLI commands (e.g., login, connect, action run, request) to manage data and workflows. These commands are standard for the integration and are executed within the user's terminal environment.
  • [PROMPT_INJECTION]: The skill processes external data from Oracle Eloqua via CLI command outputs. This data is ingested into the agent's context without specific boundary markers or sanitization, representing a surface for indirect prompt injection if external records contain malicious instructions.
  • Ingestion points: membrane action run and membrane request in SKILL.md.
  • Boundary markers: Not present.
  • Capability inventory: Shell command execution, network requests via proxy.
  • Sanitization: Not present.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 09:50 AM