ottertext
Pass
Audited by Gen Agent Trust Hub on May 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the
@membranehq/clipackage from npm, which is the official tool provided by the vendor 'membranedev' for platform interaction. This is a trusted resource within the context of the platform's intended use. - [COMMAND_EXECUTION]: Utilizes the
membraneCLI for platform interactions, including authentication and action management. These commands are part of the standard integration workflow and do not involve unsafe shell manipulation. - [SAFE]: Authentication is handled through the platform's native
loginandconnectcommands, which securely manage tokens server-side and prevent the agent from needing direct access to sensitive API keys. - [SAFE]: A metadata inconsistency was noted where the documentation link references
otter.ai(a transcription service) while describing 'OtterText' (an SMS marketing service). This appears to be a clerical error rather than a security risk.
Audit Metadata