bugsnag
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses the official Membrane CLI (
@membranehq/cli) for all operations. This follows the principle of least privilege by abstracting authentication and connection management through a centralized service. - [EXTERNAL_DOWNLOADS]: The skill installs the
@membranehq/clipackage via npm. As this is a package from the verified vendor (membranedev/membranehq), it is considered a legitimate dependency for the skill's functionality. - [CREDENTIALS_UNSAFE]: The skill explicitly instructs the agent to avoid asking users for API keys or tokens, instead delegating secret management to the Membrane platform, which is a security best practice.
Audit Metadata