brex
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads the
@membranehq/clipackage from the official NPM registry, which is a well-known and trusted service. - [COMMAND_EXECUTION]: The skill utilizes several
membraneCLI commands (login,connection create,action call,request) to manage authentication and interact with the Brex API. These commands are integral to the skill's primary purpose and are executed through a managed interface. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill follows security best practices by explicitly instructing against requesting API keys or tokens from the user. It uses Membrane's connection system to handle sensitive credentials securely.
- [TRUST-SCOPE-RULE]: References to
getmembrane.com,github.com/membranedev, and the@membranehqNPM namespace are identified as vendor resources for the provider 'membranedev' and are documented as safe.
Audit Metadata