device-magic
Pass
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill follows security best practices by recommending that authentication be handled via the platform's connection system rather than hardcoding or requesting secrets from the user.\n- [EXTERNAL_DOWNLOADS]: The skill recommends installing the Membrane CLI (@membranehq/cli) from npm. This package and the associated domains (getmembrane.com) are owned by the vendor and are necessary for the skill's functionality.\n- [SAFE]: The skill has a surface for indirect prompt injection as it processes external data. Ingestion points: form submissions (SKILL.md). Boundary markers: absent. Capability inventory: form modification and proxy requests (SKILL.md). Sanitization: absent. This is a standard characteristic of integration tools.
Audit Metadata