carapi

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the @membranehq/cli package from npm. This is the official tool provided by the platform vendor for managing integrations and authentication.
  • [COMMAND_EXECUTION]: Various CLI commands such as membrane login, membrane connect, and membrane action run are utilized to interact with the service. These commands are well-defined and restricted to the functionality required for the skill's operation.
  • [CREDENTIALS_UNSAFE]: The instructions explicitly guide the agent to avoid direct handling of sensitive API keys or tokens, instead delegating credential lifecycle management to the Membrane platform. This is a secure approach to secret management in AI agent environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 11:50 PM
Security Audit — agent-trust-hub — carapi