hyscoreio

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the @membranehq/cli package from the NPM registry. This is a legitimate tool provided by the vendor for managing integrations.
  • [COMMAND_EXECUTION]: The instructions direct the agent to use the membrane command-line tool for authentication, discovering actions, and interacting with Hyscore.io data.
  • [DATA_EXFILTRATION]: No unauthorized data transfer or credential harvesting was found. The skill explicitly recommends using the Membrane platform to handle credentials server-side, avoiding the need for local API keys.
  • [REMOTE_CODE_EXECUTION]: The skill utilizes npx to run the latest version of the vendor's CLI directly from the registry.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 10:35 PM