bigpictureio

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package from npm. This is a vendor-owned tool from the skill's authoring organization and is used for its intended purpose of platform interaction.
  • [COMMAND_EXECUTION]: The skill uses the membrane CLI to perform operations like searches, actions, and API requests. These commands are localized to the integration's functionality and do not exhibit signs of arbitrary command injection or privilege escalation.
  • [CREDENTIALS_UNSAFE]: The skill follows security best practices by explicitly advising against asking for or storing API keys or tokens locally. Instead, it utilizes the platform's built-in connection management system which handles the authentication lifecycle server-side.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 10:29 PM