lighthouse
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were identified in the skill instructions.
- [EXTERNAL_DOWNLOADS]: The skill guides the user to install the official @membranehq/cli package from the NPM registry, which is the standard distribution method for the author's tooling.
- [COMMAND_EXECUTION]: The skill uses local shell commands to interact with the Membrane CLI. These commands facilitate authentication and API interaction through the vendor's platform and do not contain patterns for arbitrary code execution or privilege escalation.
- [CREDENTIALS_UNSAFE]: The skill correctly advises users to avoid manual API key management and instead use the platform's connection system, which is a recommended security practice.
Audit Metadata