chef-inspec

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs the user to install the @membranehq/cli package from the public npm registry. This is an official tool provided by the service vendor for interacting with their platform.
  • [COMMAND_EXECUTION]: The skill uses standard CLI commands (membrane login, membrane action, membrane request) to automate security and compliance workflows. These operations are scoped to the user's authenticated session and the intended functionality of the Chef InSpec framework.
  • [CREDENTIALS_UNSAFE]: The skill demonstrates high security awareness by explicitly advising against asking for or storing API keys locally, instead leveraging the Membrane platform's server-side credential management system.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 05:22 PM
Security Audit — agent-trust-hub — chef-inspec