purple-sonar

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the @membranehq/cli package from the public npm registry. This is the official tool for the service provided by the vendor.
  • [COMMAND_EXECUTION]: Instructions involve using the membrane CLI to interact with external services. This is a standard and expected behavior for this platform integration.
  • [DATA_EXFILTRATION]: The skill implements secure authentication practices by using membrane login and membrane connect, which avoid the need for hardcoded credentials or manual API key handling.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 03:19 PM
Security Audit — agent-trust-hub — purple-sonar