ambivo

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the official @membranehq/cli package from the NPM registry. This is a standard dependency for interacting with the Membrane platform.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands (membrane login, membrane connect, membrane action run) to interact with the Ambivo service through the CLI. These commands are part of the intended integration workflow.
  • [CREDENTIALS_UNSAFE]: The skill promotes secure practices by explicitly instructing the agent to never ask the user for API keys or tokens, instead utilizing a browser-based OAuth flow managed by the platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 02:47 AM
Security Audit — agent-trust-hub — ambivo