order-desk
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the
@membranehq/clipackage globally via npm. This is a standard utility provided by the vendor (Membrane) to manage integrations. - [COMMAND_EXECUTION]: The instructions involve executing various
membraneCLI commands to perform authentication (membrane login), connection management (membrane connect), and action execution (membrane action run). These are legitimate operational commands within the context of the tool's purpose. - [CREDENTIALS_UNSAFE]: The skill follows security best practices by explicitly advising against asking for user API keys or tokens, relying instead on Membrane's server-side authentication lifecycle.
- [PROMPT_INJECTION]: No instructions were found that attempt to bypass safety filters, override system prompts, or extract sensitive model information.
Audit Metadata