hellosign

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs the user to install @membranehq/cli globally via npm. This package is the official command-line interface for the Membrane platform, which is the vendor for this skill.
  • [COMMAND_EXECUTION]: Uses various membrane CLI commands (login, connect, action run, request) to manage integration logic. These commands facilitate secure communication with the HelloSign API through the vendor's infrastructure.
  • [CREDENTIALS_UNSAFE]: The skill explicitly instructs users not to provide API keys or tokens directly, instead delegating authentication to the Membrane platform. This follows the principle of least privilege and secure secret management.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 12:50 AM