respondio

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package from npm. This is the official command-line interface provided by the vendor (Membrane) and is a recognized, safe resource within the project's ecosystem.
  • [COMMAND_EXECUTION]: The skill utilizes the membrane CLI to perform platform-specific tasks such as login, connect, and action run. These commands are standard for the integration and are restricted to the authenticated user's environment.
  • [CREDENTIALS_UNSAFE]: Secure credential management is implemented by using Membrane's connection system. The instructions explicitly advise against requesting or storing raw API keys, opting for a server-side authentication lifecycle instead.
  • [REMOTE_CODE_EXECUTION]: The skill uses npx @membranehq/cli for dynamic action discovery. Since this targets the official, versioned package of the platform vendor, it is considered a legitimate and safe use of remote package execution for tool discovery.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 04:04 PM
Security Audit — agent-trust-hub — respondio