cortex-xsoar

Pass

Audited by Gen Agent Trust Hub on May 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the @membranehq/cli package from the official npm registry. This is a vendor-provided command-line interface used to interact with the Membrane platform.
  • [COMMAND_EXECUTION]: The skill utilizes several membrane CLI commands (e.g., membrane login, membrane connect, membrane action run) to automate security workflows. These commands are part of the intended functionality for orchestrating data between the agent and the Cortex XSOAR platform.
  • [SAFE]: The skill follows secure credential management practices by explicitly instructing the agent not to ask for API keys, instead delegating authentication to the Membrane service. No malicious patterns such as obfuscation, persistence, or unauthorized data exfiltration were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
May 2, 2026, 11:49 PM
Security Audit — agent-trust-hub — cortex-xsoar