yumpu

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the @membranehq/cli package from the official NPM registry. This is a legitimate tool used to facilitate the integration and manage API interactions securely without exposing local secrets.
  • [COMMAND_EXECUTION]: The skill uses shell commands to interact with the membrane CLI. These commands are used for standard integration tasks such as logging in, creating connections, and executing specific Yumpu actions (e.g., listing documents or running workflows).
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 06:11 PM
Security Audit — agent-trust-hub — yumpu