bugsnag

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses the official Membrane CLI (@membranehq/cli) for all operations. This follows the principle of least privilege by abstracting authentication and connection management through a centralized service.
  • [EXTERNAL_DOWNLOADS]: The skill installs the @membranehq/cli package via npm. As this is a package from the verified vendor (membranedev/membranehq), it is considered a legitimate dependency for the skill's functionality.
  • [CREDENTIALS_UNSAFE]: The skill explicitly instructs the agent to avoid asking users for API keys or tokens, instead delegating secret management to the Membrane platform, which is a security best practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 02:18 PM