tmetric
Pass
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the official Membrane CLI (@membranehq/cli) from the vendor's repository to facilitate API interactions.
- [PROMPT_INJECTION]: The skill processes data from TMetric (such as tasks and time entries) which serves as a surface for indirect prompt injection. 1. Ingestion points: Output from membrane action run and membrane request (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Shell command execution via the Membrane CLI. 4. Sanitization: Absent.
Audit Metadata