prestashop

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the @membranehq/cli package from npm. This is a vendor-owned resource from the 'membranedev' author context and is a prerequisite for using the integration.\n- [COMMAND_EXECUTION]: The skill utilizes the membrane CLI to perform actions and requests against the PrestaShop API. These commands are standard operations for the integration logic and do not involve suspicious privilege escalation.\n- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes data from an external platform (PrestaShop).\n
  • Ingestion points: Data returned from PrestaShop endpoints via membrane action run and membrane request as described in SKILL.md.\n
  • Boundary markers: No explicit delimiters or warnings for the agent are present in the skill instructions.\n
  • Capability inventory: The skill can execute shell commands via the membrane CLI and perform network operations through the proxy service.\n
  • Sanitization: No explicit sanitization or validation of the external API data is described within the skill body.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 01:14 PM