updownio
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the
@membranehq/clipackage from the NPM registry. This is the official command-line interface provided by the skill's author to facilitate platform interactions. - [COMMAND_EXECUTION]: Shell commands are used via the
membraneCLI to authenticate, create connections, and run actions. These operations are standard for the intended functionality of the skill. - [DATA_EXFILTRATION]: The skill demonstrates good security posture by explicitly instructing the agent to never ask the user for API keys or tokens, instead delegating credential management to the Membrane platform.
- [PROMPT_INJECTION]: While the skill ingests data from Updown.io which could technically contain malicious content, the static instructions do not contain any patterns of prompt injection or behavior overrides.
Audit Metadata