phyllo
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: A comprehensive review of the skill's instructions and commands found no evidence of malicious intent, obfuscation, or unauthorized data access. The skill's behavior is consistent with its stated purpose of Phyllo integration.\n- [COMMAND_EXECUTION]: The skill leverages the
membraneCLI to perform searches, connections, and action executions. These commands are restricted to the functionality provided by the Membrane platform and do not involve arbitrary shell execution or unsafe user input handling.\n- [EXTERNAL_DOWNLOADS]: The skill directs users to install the@membranehq/clipackage from NPM. This is an official vendor-provided tool necessary for interacting with the Membrane ecosystem and does not constitute a security risk.\n- [SAFE]: The skill interacts with external data from the Phyllo API. While this creates a potential surface for indirect prompt injection, the risk is mitigated by using Membrane's structured actions. Ingestion points: Phyllo API data processed bymembrane action runin SKILL.md. Boundary markers: Absent. Capability inventory:membraneCLI tool calls in SKILL.md. Sanitization: Absent.
Audit Metadata