totango

Pass

Audited by Gen Agent Trust Hub on May 2, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package from the official npm registry. This is a vendor-owned resource used for its intended purpose of interacting with the Membrane platform.
  • [COMMAND_EXECUTION]: The skill uses the membrane CLI to perform operations such as authentication, connection management, and action execution. These commands are transparently documented and follow standard operational patterns for this platform.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials were found. The skill follows security best practices by instructing the agent to never ask for API keys directly and instead use Membrane's server-side connection management system.
Audit Metadata
Risk Level
SAFE
Analyzed
May 2, 2026, 02:44 AM
Security Audit — agent-trust-hub — totango