vanta

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the official Membrane CLI package (@membranehq/cli) globally from the npm registry.
  • [COMMAND_EXECUTION]: The skill uses the membrane command-line utility to perform authentication (membrane login), manage connections (membrane connect), and execute workflows.
  • [REMOTE_CODE_EXECUTION]: The commands membrane action create and membrane action run facilitate the building and execution of integration logic on the Membrane platform. This behavior is consistent with the skill's stated purpose of automating Vanta workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 11:50 PM
Security Audit — agent-trust-hub — vanta