dropbox-sign
Pass
Audited by Gen Agent Trust Hub on Mar 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation specifies the installation of the
@membranehq/clipackage from the NPM registry. This is a legitimate vendor tool for integration management.\n- [COMMAND_EXECUTION]: The skill demonstrates the use of themembranecommand-line utility for actions such as listing connections, searching for intents, and executing signature requests.\n- [DATA_EXFILTRATION]: All data interactions are conducted through Membrane's infrastructure, which manages authentication and API calls. No evidence of unauthorized network requests or local sensitive file access was found.
Audit Metadata