rasa-1
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the @membranehq/cli package from the public npm registry. As this is a vendor-owned resource used to facilitate integration with their platform, it is considered a legitimate dependency.
- [COMMAND_EXECUTION]: The skill executes commands via the membrane CLI to manage user sessions and run data actions. This behavior is transparently documented and aligns with the skill's stated purpose.
- [DATA_EXFILTRATION]: No unauthorized data transmission or exfiltration patterns were observed. The skill explicitly promotes security by instructing the agent to use the platform's server-side connection management rather than requesting or storing user API keys locally.
Audit Metadata