avaza

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Installs the @membranehq/cli package from the official npm registry. This is the vendor's standard command-line interface for managing integrations and is a well-known service component.
  • [COMMAND_EXECUTION]: Utilizes local shell commands to interact with the installed CLI for authentication and API interaction. These operations are within the scope of the skill's primary purpose.
  • [SAFE]: The skill implements secure credential management by instructing the agent to never ask users for API keys, instead using a delegated authentication flow through the Membrane platform.
  • [SAFE]: No obfuscation, prompt injection, or unauthorized network activity was detected in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 08:34 AM
Security Audit — agent-trust-hub — avaza