textit

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the 'membrane' CLI to perform actions such as searching, connecting, and running tasks. This is the primary and documented method for interacting with the service.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the '@membranehq/cli' package from the NPM registry. This is an official vendor package required for the integration to function.
  • [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface when processing external data from TextIt. * Ingestion points: Data retrieved from TextIt API actions and proxy requests described in SKILL.md. * Boundary markers: Not present in the provided instructions. * Capability inventory: Execution of actions and proxy requests via the 'membrane' CLI. * Sanitization: No explicit sanitization or filtering of external content is documented.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 06:04 PM