signrequest
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@membranehq/clipackage from the npm registry. This is a legitimate utility provided by the skill's author for interacting with their platform. - [COMMAND_EXECUTION]: The skill uses shell commands via the Membrane CLI to manage authentication and execute business logic. This is the intended operation of the skill and does not include any unauthorized or suspicious command patterns.
- [CREDENTIALS_SAFE]: The skill follows security best practices by explicitly advising against asking for or storing API keys. Instead, it leverages the Membrane platform to handle OAuth and credential lifecycles server-side.
Audit Metadata