updownio

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the @membranehq/cli package from the NPM registry. This is the official command-line interface provided by the skill's author to facilitate platform interactions.
  • [COMMAND_EXECUTION]: Shell commands are used via the membrane CLI to authenticate, create connections, and run actions. These operations are standard for the intended functionality of the skill.
  • [DATA_EXFILTRATION]: The skill demonstrates good security posture by explicitly instructing the agent to never ask the user for API keys or tokens, instead delegating credential management to the Membrane platform.
  • [PROMPT_INJECTION]: While the skill ingests data from Updown.io which could technically contain malicious content, the static instructions do not contain any patterns of prompt injection or behavior overrides.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 11:40 AM