solcast

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses the @membranehq/cli package for its operations. This is a scoped package belonging to the verified author 'membranedev' and is used as intended for service integration.
  • [SAFE]: Credential management is handled through Membrane's server-side connection system (membrane connect). This approach prevents the exposure of sensitive API keys or tokens within the agent's environment or the skill's instructions.
  • [COMMAND_EXECUTION]: The skill executes shell commands via the membrane CLI to interact with the Solcast API. These commands are limited to the intended functionality of managing solar data connections and actions.
  • [SAFE]: While the skill ingests external data from the Solcast API via CLI output, this is the primary purpose of the integration.
  • Ingestion points: CLI output from membrane action run and membrane action list in SKILL.md.
  • Boundary markers: Not explicitly defined in instructions.
  • Capability inventory: Subprocess execution of the membrane CLI in SKILL.md.
  • Sanitization: Standard CLI output processing is assumed.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 09:11 AM
Security Audit — agent-trust-hub — solcast