signrequest

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package from the npm registry. This is a legitimate utility provided by the skill's author for interacting with their platform.
  • [COMMAND_EXECUTION]: The skill uses shell commands via the Membrane CLI to manage authentication and execute business logic. This is the intended operation of the skill and does not include any unauthorized or suspicious command patterns.
  • [CREDENTIALS_SAFE]: The skill follows security best practices by explicitly advising against asking for or storing API keys. Instead, it leverages the Membrane platform to handle OAuth and credential lifecycles server-side.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 03:48 AM
Security Audit — agent-trust-hub — signrequest