semaphore

Pass

Audited by Gen Agent Trust Hub on Mar 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli package from npm to function.
  • [COMMAND_EXECUTION]: The skill executes multiple shell commands using the membrane binary to manage connections, list actions, and perform API requests.
  • [PROMPT_INJECTION]: Indirect injection surface detected. 1. Ingestion points: Data retrieved from Semaphore projects, environments, or logs via membrane action run and membrane request. 2. Boundary markers: Absent. No specific delimiters or instructions to ignore embedded content are provided in the skill instructions. 3. Capability inventory: Execution of API actions and raw HTTP requests via the membrane CLI tool. 4. Sanitization: None mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 12, 2026, 06:32 AM