truv

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs and uses the official Membrane CLI package (@membranehq/cli) from the public npm registry. This is an expected vendor dependency for performing data integrations through the Membrane platform.
  • [COMMAND_EXECUTION]: The skill uses the membrane CLI to execute tasks such as authentication, connection management, and running specific data actions. These commands are part of the intended functionality and are used to interact with the vendor's managed environment.
  • [DATA_EXFILTRATION]: There is no evidence of unauthorized data access or exfiltration. The skill explicitly instructs the agent not to request API keys or tokens from the user, relying instead on server-side connection management, which minimizes the risk of credential exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 04:43 AM