macrometa
Pass
Audited by Gen Agent Trust Hub on May 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on the
membraneCLI to manage connections and execute actions. Commands likemembrane login,membrane connect, andmembrane action runare used to interface with the Macrometa database through the Membrane platform. - [EXTERNAL_DOWNLOADS]: The skill requires the
@membranehq/clipackage, which is downloaded from the npm registry. This is a vendor-owned tool necessary for the skill's operation. - [REMOTE_CODE_EXECUTION]: The skill uses
npxto dynamically fetch and execute the latest version of the@membranehq/clitool. Since this originates from a known vendor and is the intended method for utilizing the platform, it is considered a legitimate operational pattern.
Audit Metadata