product-hunt

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the official Membrane CLI from NPM (@membranehq/cli). This is a standard installation from a well-known service provider and is considered safe practice for this integration.
  • [COMMAND_EXECUTION]: The skill uses local shell commands (membrane login, membrane connection ensure, membrane action run) to interact with the Product Hunt API via the Membrane proxy. These commands are part of the intended functionality and do not involve arbitrary or malicious code execution.
  • [CREDENTIALS_SAFE]: The skill explicitly follows best practices by advising against asking users for API keys or tokens. It utilizes an OAuth-based flow where credentials are managed server-side by Membrane, reducing the risk of local credential exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:13 PM
Security Audit — agent-trust-hub — product-hunt