toneden
Pass
Audited by Gen Agent Trust Hub on Apr 3, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the
@membranehq/clipackage, which is the official tooling provided by the vendor for this integration. - [COMMAND_EXECUTION]: The skill utilizes the
membranecommand-line utility to perform authentication, search for connectors, and execute actions against the ToneDen API. - [PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection by processing external data from ToneDen.
- Ingestion points: Data retrieved via
membrane action runandmembrane requestcommands (SKILL.md). - Boundary markers: No specific delimiters or warnings are defined for external content.
- Capability inventory: The skill can execute API actions and arbitrary HTTP requests via the CLI (SKILL.md).
- Sanitization: No specific sanitization or filtering logic is mentioned for the processed data.
Audit Metadata