tenderly

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the @membranehq/cli package from NPM. This is an official utility provided by the vendor to facilitate secure communication with the platform.\n- [COMMAND_EXECUTION]: Uses the membrane CLI to perform tasks such as authentication, searching for elements, and executing API actions. These commands are integral to the skill's functionality as a management tool.\n- [SAFE]: The skill promotes secure development practices by using the platform's managed connection system, which handles credential storage and refresh automatically instead of requiring users to manage API keys manually.\n- [PROMPT_INJECTION]: The skill processes external data from Tenderly which may contain untrusted instructions (Indirect Prompt Injection). Evidence Chain: 1. Ingestion points: Data returned from membrane action run and membrane request. 2. Boundary markers: Absent in the provided instructions. 3. Capability inventory: Execution of shell commands via the CLI. 4. Sanitization: No explicit data sanitization or filtering logic is described in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 05:10 PM