rasa-1

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the @membranehq/cli package from the public npm registry. As this is a vendor-owned resource used to facilitate integration with their platform, it is considered a legitimate dependency.
  • [COMMAND_EXECUTION]: The skill executes commands via the membrane CLI to manage user sessions and run data actions. This behavior is transparently documented and aligns with the skill's stated purpose.
  • [DATA_EXFILTRATION]: No unauthorized data transmission or exfiltration patterns were observed. The skill explicitly promotes security by instructing the agent to use the platform's server-side connection management rather than requesting or storing user API keys locally.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 10:06 AM