textit
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the 'membrane' CLI to perform actions such as searching, connecting, and running tasks. This is the primary and documented method for interacting with the service.
- [EXTERNAL_DOWNLOADS]: The skill utilizes the '@membranehq/cli' package from the NPM registry. This is an official vendor package required for the integration to function.
- [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface when processing external data from TextIt. * Ingestion points: Data retrieved from TextIt API actions and proxy requests described in SKILL.md. * Boundary markers: Not present in the provided instructions. * Capability inventory: Execution of actions and proxy requests via the 'membrane' CLI. * Sanitization: No explicit sanitization or filtering of external content is documented.
Audit Metadata