sage-hr

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli package from the official npm registry. This is a legitimate tool provided by the vendor (membranedev) to facilitate the integration.
  • [COMMAND_EXECUTION]: The skill uses shell commands to interact with the Membrane CLI for managing HR data. This includes logging in, connecting to services, and executing pre-built or dynamically generated actions within the Membrane environment.
  • [CREDENTIALS_UNSAFE]: The skill demonstrates safe credential handling. It instructs the agent to use Membrane's server-side authentication flow, specifically advising against asking users for API keys or tokens and ensuring no secrets are stored in the local environment.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 10:28 PM