maestra

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user or agent to install the @membranehq/cli package via npm. This is a standard utility provided by the vendor for managing integrations.
  • [COMMAND_EXECUTION]: The skill uses several CLI commands (membrane login, membrane connect, membrane action run, etc.) to interact with the Membrane platform. These commands are the primary intended interface for the skill's functionality and do not exhibit suspicious patterns.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill explicitly advises against asking users for API keys or tokens, recommending the use of managed connections to handle the authentication lifecycle securely on the server side.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 08:12 PM
Security Audit — agent-trust-hub — maestra