vultr

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute various shell commands using the Membrane CLI (membrane) to manage Vultr resources, including membrane login, membrane connect, and membrane action run.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli package from the NPM registry to function, which is a standard dependency for the vendor's ecosystem.
  • [PROMPT_INJECTION]: The skill contains a surface for indirect prompt injection (Category 8) due to its ability to ingest and act upon external data.
  • Ingestion points: Data retrieved from the Vultr API via membrane request and metadata retrieved via membrane action list (SKILL.md).
  • Boundary markers: Absent; the instructions do not specify the use of delimiters or provide warnings to the agent regarding potentially malicious content in API responses.
  • Capability inventory: The skill can perform significant cloud infrastructure modifications (e.g., managing virtual machines, SSH keys, and firewall groups) via membrane action run and membrane request (SKILL.md).
  • Sanitization: Absent; there is no mention of validating or sanitizing retrieved API data before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 04:11 PM