alphamoon
Pass
Audited by Gen Agent Trust Hub on May 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use shell commands via the
membraneCLI. These commands handle authentication (membrane login), connection setup (membrane connect), and the execution of integration actions (membrane action run). These are standard operations for a CLI-driven integration. - [EXTERNAL_DOWNLOADS]: The instructions require installing the
@membranehq/clipackage from the NPM registry. This is the official tool provided by the skill's author (Membrane) to facilitate secure integrations. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill manages data from Alphamoon but uses a brokered authentication model. By using the Membrane platform to handle OAuth flows and credentials server-side, the skill avoids exposing sensitive tokens directly within the agent's prompts or local environment.
Audit Metadata