worldline

Pass

Audited by Gen Agent Trust Hub on Apr 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill guides the user to install the @membranehq/cli tool from npm, which is an official package maintained by the skill's author (membranedev).
  • [COMMAND_EXECUTION]: Uses the membrane command-line interface to interact with Worldline APIs, including managing connections and executing payment-related actions.
  • [CREDENTIALS_UNSAFE]: Demonstrates secure credential management by leveraging Membrane's server-side authentication system, explicitly avoiding the use of hardcoded API keys.
  • [PROMPT_INJECTION]: The skill processes data from the Worldline API (Ingestion point: membrane action run and membrane request in SKILL.md), representing a surface for indirect prompt injection. Capability inventory includes subprocess execution via the CLI. However, no malicious instructions or bypass attempts were detected, and the underlying platform provides the necessary sanitization logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 3, 2026, 06:44 AM