purple-dot
Pass
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the
@membranehq/clipackage globally via npm, which is the vendor's official tool for interacting with their platform. This is a standard dependency for skills utilizing the Membrane ecosystem.\n- [COMMAND_EXECUTION]: Utilizes themembraneCLI to perform operational tasks such as logging in, searching for connectors, and executing remote actions or proxy requests to the Purple Dot API.\n- [SAFE]: Sensitive authentication credentials are not handled or stored directly by the skill. Instead, they are managed by the vendor's service through a secure browser-based login flow, which adheres to security best practices for credential management.
Audit Metadata