build-product-integrations
Pass
Audited by Gen Agent Trust Hub on Mar 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill utilizes the official Membrane CLI (@membranehq/cli) and SDKs for integration management. All external resources point to trusted vendor domains including getmembrane.com and integration.app.\n- [SAFE]: Authentication mechanisms follow industry standards, using JWT tokens generated on the backend to avoid exposing secrets to the frontend. CLI credentials are stored locally with appropriate file permissions.\n- [PROMPT_INJECTION]: Indirect prompt injection surface identified. 1. Ingestion points: User-provided intents in CLI search and messages in agent session creation. 2. Boundary markers: Absent in CLI examples. 3. Capability inventory: Execution of actions and creation of integration elements via the @membranehq/cli tool. 4. Sanitization: Not specified in instructions. This surface is intrinsic to the skill's primary purpose of using AI to build and run integrations.\n- [SAFE]: No evidence of code obfuscation, persistence mechanisms, or unauthorized privilege escalation was found in the provided instructions.
Audit Metadata