formance

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the membrane CLI to perform operations. These commands are restricted to managing connections and executing financial actions within the Formance ecosystem.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package via npm. This is a verified vendor resource belonging to the skill author (Membrane) and is required for the skill's operation.
  • [CREDENTIALS_UNSAFE]: The skill promotes secure authentication practices. It explicitly instructs the agent to avoid asking users for API keys, instead using membrane login and membrane connect to manage tokens through the vendor's secure infrastructure.
  • [DATA_EXFILTRATION]: No suspicious data exfiltration patterns were identified. Network communication is limited to the vendor's platform and official documentation sites.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 10:02 AM
Security Audit — agent-trust-hub — formance