truora
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@membranehq/clipackage globally via npm. This is the official CLI tool provided by the vendor (Membrane) to facilitate platform integrations. - [COMMAND_EXECUTION]: The agent is directed to execute various shell commands using the
membraneCLI, such asmembrane loginfor authentication,membrane connectfor linking Truora accounts, andmembrane actionfor executing data operations. These commands are necessary for the skill's stated purpose of managing Truora data. - [DATA_EXFILTRATION]: While the skill retrieves sensitive identity and background check data from Truora, it does so through an authenticated connection managed by the Membrane platform. No patterns of unauthorized data exfiltration were detected.
Audit Metadata