scaled-access

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the @membranehq/cli package from the public NPM registry. This is the official command-line tool provided by the vendor (Membrane) to interact with their services.
  • [COMMAND_EXECUTION]: The skill utilizes several membrane CLI commands to handle authentication (membrane login), connection management (membrane connect), and the execution of automated tasks (membrane action run). These operations are consistent with the skill's stated purpose of managing access governance.
  • [DATA_EXFILTRATION]: No sensitive data exposure or unauthorized exfiltration patterns were identified. The instructions emphasize using the platform's connection management to avoid handling raw API keys or tokens directly, which aligns with secure credential management practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 12:06 AM