deepseek
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the Membrane CLI from the official NPM registry using
npm install -g @membranehq/cli@latest. This is a standard installation procedure for a well-known developer tool. - [COMMAND_EXECUTION]: The skill utilizes the
membraneCLI to manage connections, search for actions, and execute requests. These operations are scoped to the vendor's platform and do not involve arbitrary shell execution of untrusted input. - [CREDENTIALS_SAFE]: The skill explicitly advises against asking users for API keys, instead utilizing
membrane connection ensureto handle authentication server-side. This aligns with secure secret management practices. - [DATA_EXFILTRATION]: While the skill performs network operations via the
membraneCLI to DeepSeek endpoints, it does not access sensitive local system files (like SSH keys or AWS credentials) or exfiltrate them to unauthorized domains.
Audit Metadata