vivocalendar
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the
@membranehq/clipackage from the official NPM registry. This is a legitimate tool provided by the vendor (membranedev) for interacting with their ecosystem. - [SAFE]: Authentication is managed securely through the
membrane loginandmembrane connectcommands, which use browser-based OAuth flows. This prevents the need for hardcoding or manually handling sensitive API credentials. - [SAFE]: All identified command patterns (e.g.,
membrane action run,membrane request) are standard operations for the platform and do not exhibit signs of malicious intent or unauthorized data access. - [SAFE]: No patterns of prompt injection, code obfuscation, or persistence mechanisms were detected in the skill instructions.
Audit Metadata