shieldpay

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package from the public NPM registry. This is a standard requirement for interacting with the vendor's platform and originates from a vendor-controlled package scope.
  • [COMMAND_EXECUTION]: The instructions involve executing various membrane CLI commands to manage authentication, search for actions, and run integration tasks. These are intended functional operations for the platform.
  • [CREDENTIALS_UNSAFE]: The skill explicitly advises against manual credential management and instead uses a secure delegated authentication flow (membrane login) which keeps sensitive tokens out of the prompt context and local configuration files.
  • [DATA_EXFILTRATION]: No unauthorized network operations or exfiltration patterns were detected. All network activity is mediated through the official CLI tool to the vendor's infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 01:44 AM
Security Audit — agent-trust-hub — shieldpay