chef-inspec
Pass
Audited by Gen Agent Trust Hub on Apr 30, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill directs the user to install the
@membranehq/clipackage from the public npm registry. This is an official tool provided by the service vendor for interacting with their platform. - [COMMAND_EXECUTION]: The skill uses standard CLI commands (
membrane login,membrane action,membrane request) to automate security and compliance workflows. These operations are scoped to the user's authenticated session and the intended functionality of the Chef InSpec framework. - [CREDENTIALS_UNSAFE]: The skill demonstrates high security awareness by explicitly advising against asking for or storing API keys locally, instead leveraging the Membrane platform's server-side credential management system.
Audit Metadata