bigpictureio
Pass
Audited by Gen Agent Trust Hub on Apr 21, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
@membranehq/clipackage from npm. This is a vendor-owned tool from the skill's authoring organization and is used for its intended purpose of platform interaction. - [COMMAND_EXECUTION]: The skill uses the
membraneCLI to perform operations like searches, actions, and API requests. These commands are localized to the integration's functionality and do not exhibit signs of arbitrary command injection or privilege escalation. - [CREDENTIALS_UNSAFE]: The skill follows security best practices by explicitly advising against asking for or storing API keys or tokens locally. Instead, it utilizes the platform's built-in connection management system which handles the authentication lifecycle server-side.
Audit Metadata