Insightly
PassAudited by VirusTotal on Apr 30, 2026.
Findings (1)
The skill requires high-risk operations including the global installation of the `@membranehq/cli` npm package and the execution of shell commands to manage authentication and API requests via a third-party proxy (getmembrane.com). A significant indicator is the documentation in `SKILL.md` describing a mechanism where the agent may receive and follow dynamic `agentInstructions` from a remote server during the connection process, which could serve as a vector for remote instruction injection. Additionally, the `_meta.json` file contains a future-dated timestamp (May 2026), which is an unusual metadata anomaly.
