campay
Pass
Audited by Gen Agent Trust Hub on Apr 30, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill relies on the
@membranehq/cliNode.js package, which is a legitimate resource provided by the author (membranedev) for interacting with their platform.\n- [SAFE]: Authentication is handled through a securemembrane loginflow, which delegates credential management to the Membrane platform. This prevents sensitive API keys from being exposed in the agent's context or configuration files.\n- [SAFE]: No evidence of prompt injection, obfuscation, or unauthorized network activity was found. The instructions focus on standard administrative and operational tasks within the CamPay/Membrane ecosystem.\n- [SAFE]: While the skill processes data from external actions (membrane action run), which is a surface for indirect prompt injection, it does so within a structured integration framework that emphasizes security best practices.
Audit Metadata