usercom

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the Membrane CLI tool using the command npm install -g @membranehq/cli@latest from the official npm registry. This is standard installation procedure for the vendor's own tooling.
  • [COMMAND_EXECUTION]: Utilizes the membrane CLI for managing platform authentication (membrane login), creating connections (membrane connect), and discovering or executing actions (membrane action). These operations are scoped to the Membrane service environment.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: Explicitly recommends against manual API key handling, instead using Membrane's server-side connection management to ensure credentials are never stored locally or handled by the agent directly.
  • [INDIRECT_PROMPT_INJECTION]: The skill uses natural language descriptions to search for or dynamically generate new actions via the membrane action list and membrane action create commands. While this introduces a surface for indirect instructions, the logic is processed through the Membrane platform's structured action system.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 06:42 AM
Security Audit — agent-trust-hub — usercom