truora

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package globally via npm. This is the official CLI tool provided by the vendor (Membrane) to facilitate platform integrations.
  • [COMMAND_EXECUTION]: The agent is directed to execute various shell commands using the membrane CLI, such as membrane login for authentication, membrane connect for linking Truora accounts, and membrane action for executing data operations. These commands are necessary for the skill's stated purpose of managing Truora data.
  • [DATA_EXFILTRATION]: While the skill retrieves sensitive identity and background check data from Truora, it does so through an authenticated connection managed by the Membrane platform. No patterns of unauthorized data exfiltration were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 04:43 AM