Exa

PassAudited by VirusTotal on May 11, 2026.

Findings (1)

The skill instructs the agent to perform a global system modification via 'npm install -g @membranehq/cli' and mandates routing all API traffic and authentication through a third-party intermediary (Membrane). While these actions are aligned with the stated purpose of using the Membrane platform for integration, the requirement for global software installation and the redirection of data through an external proxy are high-risk patterns. Furthermore, the _meta.json file contains a future-dated publication timestamp (April 2026), which is an unusual anomaly.