tinyurl
Pass
Audited by Gen Agent Trust Hub on May 5, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the
@membranehq/clipackage from the official NPM registry. This is the legitimate tool provided by the vendor for platform interaction. - [COMMAND_EXECUTION]: Utilizes the
membraneCLI utility to perform authentication and manage API connections. These commands are standard operations for the platform and do not involve unauthorized access or exfiltration. - [REMOTE_CODE_EXECUTION]: Employs the
membrane action createcommand, which triggers a build process on the vendor's platform to generate API integration logic. This is an intended architectural feature of the Membrane ecosystem for dynamic action creation.
Audit Metadata