deepseek

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the Membrane CLI from the official NPM registry using npm install -g @membranehq/cli@latest. This is a standard installation procedure for a well-known developer tool.
  • [COMMAND_EXECUTION]: The skill utilizes the membrane CLI to manage connections, search for actions, and execute requests. These operations are scoped to the vendor's platform and do not involve arbitrary shell execution of untrusted input.
  • [CREDENTIALS_SAFE]: The skill explicitly advises against asking users for API keys, instead utilizing membrane connection ensure to handle authentication server-side. This aligns with secure secret management practices.
  • [DATA_EXFILTRATION]: While the skill performs network operations via the membrane CLI to DeepSeek endpoints, it does not access sensitive local system files (like SSH keys or AWS credentials) or exfiltrate them to unauthorized domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:12 PM
Security Audit — agent-trust-hub — deepseek