brex

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the @membranehq/cli package from the official NPM registry, which is a well-known and trusted service.
  • [COMMAND_EXECUTION]: The skill utilizes several membrane CLI commands (login, connection create, action call, request) to manage authentication and interact with the Brex API. These commands are integral to the skill's primary purpose and are executed through a managed interface.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill follows security best practices by explicitly instructing against requesting API keys or tokens from the user. It uses Membrane's connection system to handle sensitive credentials securely.
  • [TRUST-SCOPE-RULE]: References to getmembrane.com, github.com/membranedev, and the @membranehq NPM namespace are identified as vendor resources for the provider 'membranedev' and are documented as safe.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:35 PM
Security Audit — agent-trust-hub — brex