formstack

Pass

Audited by Gen Agent Trust Hub on May 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the Membrane CLI tool (@membranehq/cli) from the official npm registry, which is a vendor-owned resource used for the integration.
  • [COMMAND_EXECUTION]: The instructions guide the agent to use shell commands via the membrane CLI to authenticate, manage connections, and perform CRUD operations on Formstack resources.
  • [DATA_EXFILTRATION]: The skill processes potentially sensitive data from Formstack, such as form submissions and user details. However, it leverages a managed platform that handles credentials server-side, reducing the risk of local secret exposure.
  • [REMOTE_CODE_EXECUTION]: The membrane action create functionality allows for the dynamic generation of integration logic based on natural language descriptions, which is a core feature of the vendor's platform used to build actions on their infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
May 4, 2026, 11:50 PM
Security Audit — agent-trust-hub — formstack