sage-hr
Pass
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
@membranehq/clipackage from the official npm registry. This is a legitimate tool provided by the vendor (membranedev) to facilitate the integration. - [COMMAND_EXECUTION]: The skill uses shell commands to interact with the Membrane CLI for managing HR data. This includes logging in, connecting to services, and executing pre-built or dynamically generated actions within the Membrane environment.
- [CREDENTIALS_UNSAFE]: The skill demonstrates safe credential handling. It instructs the agent to use Membrane's server-side authentication flow, specifically advising against asking users for API keys or tokens and ensuring no secrets are stored in the local environment.
Audit Metadata