moov
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@membranehq/clipackage from the official NPM registry. This is a standard procedure for using the author's development tools. - [COMMAND_EXECUTION]: Utilizes several CLI commands including
membrane login,membrane connect, andmembrane action runto manage authentication and interact with the Moov API. These are well-defined operations within the vendor's ecosystem. - [REMOTE_CODE_EXECUTION]: The skill facilitates the creation and execution of custom actions via
membrane action createandmembrane action run. This behavior is the primary intended function of the Membrane platform for integrating external services. - [DATA_EXFILTRATION]: No unauthorized data transmission was detected. Communication is directed to official endpoints for Moov (moov.io) and Membrane (getmembrane.com).
Audit Metadata