planning-center

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the official @membranehq/cli from the NPM registry to facilitate communication with the Membrane platform.
  • [COMMAND_EXECUTION]: Uses the membrane CLI to perform authentication, search for actions, and run API requests.
  • [DATA_EXFILTRATION]: Sends requests to Planning Center API endpoints through the Membrane proxy service, which manages authentication headers and credential refreshes.
  • [PROMPT_INJECTION]: The skill acts as a surface for indirect prompt injection as it processes untrusted data from the Planning Center API (e.g., person records, event descriptions).
  • Ingestion points: External data retrieved via membrane action run and membrane request commands described in SKILL.md.
  • Boundary markers: No specific delimiters are defined in the instructions for separating untrusted data from agent instructions.
  • Capability inventory: Shell command execution via the membrane CLI utility.
  • Sanitization: Not explicitly implemented in the skill instructions; relies on the agent's underlying safety filters.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 03:53 AM