purple-dot

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the @membranehq/cli package globally via npm, which is the vendor's official tool for interacting with their platform. This is a standard dependency for skills utilizing the Membrane ecosystem.\n- [COMMAND_EXECUTION]: Utilizes the membrane CLI to perform operational tasks such as logging in, searching for connectors, and executing remote actions or proxy requests to the Purple Dot API.\n- [SAFE]: Sensitive authentication credentials are not handled or stored directly by the skill. Instead, they are managed by the vendor's service through a secure browser-based login flow, which adheres to security best practices for credential management.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 03:53 AM