timely-time-tracking
Pass
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses the official Membrane CLI (
@membranehq/cli) for authentication and API interaction, which is a verified vendor resource for this integration. - [SAFE]: Credential management is handled securely through the platform's OAuth flow (
membrane login), preventing the exposure of API keys or secrets within the skill instructions or user environment. - [EXTERNAL_DOWNLOADS]: The instructions guide the user to install the vendor-provided CLI package from the public npm registry, which is standard procedure for this toolset.
- [SAFE]: No instances of prompt injection, data exfiltration patterns, or obfuscated commands were identified in the provided documentation.
Audit Metadata