campay

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill relies on the @membranehq/cli Node.js package, which is a legitimate resource provided by the author (membranedev) for interacting with their platform.\n- [SAFE]: Authentication is handled through a secure membrane login flow, which delegates credential management to the Membrane platform. This prevents sensitive API keys from being exposed in the agent's context or configuration files.\n- [SAFE]: No evidence of prompt injection, obfuscation, or unauthorized network activity was found. The instructions focus on standard administrative and operational tasks within the CamPay/Membrane ecosystem.\n- [SAFE]: While the skill processes data from external actions (membrane action run), which is a surface for indirect prompt injection, it does so within a structured integration framework that emphasizes security best practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 01:10 AM