upwave

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli package from the NPM registry. This tool is necessary for the agent to interact with the Membrane platform and is a verified resource from the skill's author.
  • [COMMAND_EXECUTION]: The agent is instructed to run various membrane CLI commands to perform tasks like logging in, creating connections, and executing actions. This is the intended behavior for automating workflows via the Membrane infrastructure.
  • [SAFE]: The instructions emphasize security by directing the agent to use Membrane connections rather than requesting sensitive API keys or tokens from the user. This approach ensures that credentials remain managed by the platform rather than being exposed in the local environment or agent logs.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 09:23 PM
Security Audit — agent-trust-hub — upwave