tinfoil-security
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the
@membranehq/clipackage from the official npm registry. This is a legitimate vendor-provided tool intended for managing integrations on the Membrane platform. - [COMMAND_EXECUTION]: The skill utilizes the
membraneCLI to handle authentication, connection management, and action execution. These commands are standard operations for the integration and do not involve unauthorized system modifications. - [SAFE]: The skill explicitly recommends using the platform's connection manager to handle credentials, which prevents the exposure of sensitive API keys or tokens within the agent's execution environment.
- [SAFE]: No malicious patterns such as prompt injection, obfuscation, or unauthorized data exfiltration were detected. All described behaviors align with the skill's primary purpose of managing Tinfoil Security workflows.
Audit Metadata