hyscoreio
Pass
Audited by Gen Agent Trust Hub on Apr 30, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the
@membranehq/clipackage from the NPM registry. This is a legitimate tool provided by the vendor for managing integrations. - [COMMAND_EXECUTION]: The instructions direct the agent to use the
membranecommand-line tool for authentication, discovering actions, and interacting with Hyscore.io data. - [DATA_EXFILTRATION]: No unauthorized data transfer or credential harvesting was found. The skill explicitly recommends using the Membrane platform to handle credentials server-side, avoiding the need for local API keys.
- [REMOTE_CODE_EXECUTION]: The skill utilizes
npxto run the latest version of the vendor's CLI directly from the registry.
Audit Metadata