demandware

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the @membranehq/cli package from the official NPM registry. This is the primary tool for interacting with the vendor's services and is a standard dependency for the skill's intended functionality.
  • [COMMAND_EXECUTION]: The skill utilizes several CLI commands (membrane login, membrane connect, membrane action) to manage authentication and perform data operations. These commands are integral to the skill's workflow for managing e-commerce data.
  • [CREDENTIALS_UNSAFE]: The instructions explicitly promote safe credential handling by using a delegated OAuth flow via the CLI and advising the agent to never ask the user for raw API keys or tokens.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 10:19 AM