checkoutcom

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the @membranehq/cli package from the official npm registry. This is a legitimate utility provided by the skill author's organization for platform interaction.
  • [COMMAND_EXECUTION]: The instructions utilize the membrane command-line interface to perform administrative and operational tasks such as user login, service connection, and executing payment-related actions. These commands are standard for the intended workflow.
  • [SAFE]: No indicators of prompt injection, data exfiltration, or malicious persistence were found. The skill explicitly advises against requesting sensitive API keys directly from the user, leveraging Membrane's server-side authentication instead.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 06:50 PM