hello-retail
Pass
Audited by Gen Agent Trust Hub on Apr 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the official Membrane CLI tool (
@membranehq/cli) from the npm registry. This is a legitimate dependency provided by the skill's author. - [COMMAND_EXECUTION]: All interactions with the Hello Retail service are performed via shell commands using the
membraneCLI, which handles authentication and action logic. - [SAFE]: No malicious patterns, such as unauthorized data exfiltration, credential theft, or obfuscation, were detected. The skill properly instructs the user to use an OAuth-based login flow rather than providing raw API keys.
Audit Metadata