boxhero
Pass
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions include installing the
@membranehq/clipackage from the official NPM registry. This is a standard procedure for utilizing the vendor's command-line interface tools. - [COMMAND_EXECUTION]: The skill utilizes shell commands to interact with the BoxHero API via the Membrane CLI. These operations (search, connect, action run) are necessary for the skill's functionality and are performed through the vendor's own tooling.
- [SAFE]: The skill explicitly promotes security best practices by instructing the agent to never ask for API keys or tokens, instead using the Membrane platform for managed authentication and credential lifecycle management.
Audit Metadata