shieldpay
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@membranehq/clipackage from the public NPM registry. This is a standard requirement for interacting with the vendor's platform and originates from a vendor-controlled package scope. - [COMMAND_EXECUTION]: The instructions involve executing various
membraneCLI commands to manage authentication, search for actions, and run integration tasks. These are intended functional operations for the platform. - [CREDENTIALS_UNSAFE]: The skill explicitly advises against manual credential management and instead uses a secure delegated authentication flow (
membrane login) which keeps sensitive tokens out of the prompt context and local configuration files. - [DATA_EXFILTRATION]: No unauthorized network operations or exfiltration patterns were detected. All network activity is mediated through the official CLI tool to the vendor's infrastructure.
Audit Metadata