nowsecure

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the Membrane CLI (@membranehq/cli) globally via npm. This package is a vendor-owned resource provided by Membrane to manage integrations and authentication.
  • [COMMAND_EXECUTION]: The skill utilizes several shell commands via the membrane CLI to perform lifecycle operations, including logging in, connecting to the NowSecure service, and searching for or running actions. These commands are standard for the tool's intended purpose.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill documentation emphasizes that authentication and credential management are handled server-side by the Membrane platform, which avoids storing sensitive API keys or tokens in the local environment or the agent's prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 02:31 PM
Security Audit — agent-trust-hub — nowsecure