aikido-security
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@membranehq/clipackage from the public NPM registry. This tool is a legitimate resource provided by the vendor for managing integrations. - [COMMAND_EXECUTION]: The instructions involve executing shell commands using the
membraneCLI to authenticate, connect to services, and run automated actions. These are functional requirements for the skill's stated purpose. - [CREDENTIALS_UNSAFE]: The skill explicitly advises against manual credential handling, instructing users to let the platform manage the authentication lifecycle server-side, which is a recommended security practice.
Audit Metadata