prestashop
Pass
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the
@membranehq/clipackage from npm. This is a vendor-owned resource from the 'membranedev' author context and is a prerequisite for using the integration.\n- [COMMAND_EXECUTION]: The skill utilizes themembraneCLI to perform actions and requests against the PrestaShop API. These commands are standard operations for the integration logic and do not involve suspicious privilege escalation.\n- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes data from an external platform (PrestaShop).\n - Ingestion points: Data returned from PrestaShop endpoints via
membrane action runandmembrane requestas described in SKILL.md.\n - Boundary markers: No explicit delimiters or warnings for the agent are present in the skill instructions.\n
- Capability inventory: The skill can execute shell commands via the
membraneCLI and perform network operations through the proxy service.\n - Sanitization: No explicit sanitization or validation of the external API data is described within the skill body.
Audit Metadata