cincopa

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package from the official npm registry. This is a vendor-owned CLI tool used to facilitate the integration.
  • [COMMAND_EXECUTION]: The skill uses various membrane CLI commands to manage authentication, discover API actions, and execute workflows. These are standard operations for the intended platform integration.
  • [CREDENTIALS_UNSAFE]: The documentation includes a best practice section that explicitly advises against asking users for API keys or tokens, instead directing them to use the platform's connection management system.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 10:35 PM
Security Audit — agent-trust-hub — cincopa