dropbox-sign

Pass

Audited by Gen Agent Trust Hub on Mar 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation specifies the installation of the @membranehq/cli package from the NPM registry. This is a legitimate vendor tool for integration management.\n- [COMMAND_EXECUTION]: The skill demonstrates the use of the membrane command-line utility for actions such as listing connections, searching for intents, and executing signature requests.\n- [DATA_EXFILTRATION]: All data interactions are conducted through Membrane's infrastructure, which manages authentication and API calls. No evidence of unauthorized network requests or local sensitive file access was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 14, 2026, 05:24 PM