Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Digital Manager Guru
v1.0.0Digital Manager Guru integration. Manage data, records, and automate workflows. Use when the user wants to interact with Digital Manager Guru data.
⭐ 0· 54·0 current·0 all-time
byMembrane Dev@membranedev
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
medium confidencePurpose & Capability
The name/description match the instructions: the skill is an integration that uses Membrane to manage Digital Manager Guru data. Required tools and actions (membrane CLI, connector/connection flow, action run, proxy requests) are coherent with that purpose.
Instruction Scope
Instructions are limited to installing and using the Membrane CLI, logging in, creating connections, listing/running actions, and optionally proxying raw API requests. They do not instruct reading local files or environment secrets. However, the proxy feature permits sending arbitrary request payloads through Membrane’s servers — expected for this integration but a privacy/data‑exfiltration surface the user should be aware of.
Install Mechanism
There is no packaged installer in the skill; the README instructs installing @membranehq/cli via npm (-g). Installing a global npm package is a common but moderately risky action because it runs third‑party code on your machine — verify the npm package and publisher before installing.
Credentials
The skill requests no environment variables, system paths, or unrelated credentials. It intentionally delegates authentication to Membrane (connection-based browser auth) and explicitly advises against collecting API keys locally.
Persistence & Privilege
The skill is instruction‑only, does not request always:true, and does not modify other skills or system settings. It operates at user invocation/autonomous invocation levels normally allowed by the platform.
Assessment
This skill appears to do what it says: it uses the Membrane CLI to talk to Digital Manager Guru. Before installing/using it, verify the @membranehq/cli package on npm (publisher, downloads, repo), confirm the getmembrane.com/privacy and security posture, and review what data you'll send through Membrane's proxy (avoid sending secrets or highly sensitive data). If you must install the CLI, prefer installing in a controlled environment (container or VM) rather than system-wide, and inspect the npm package source or repository first.Like a lobster shell, security has layers — review code before you run it.
latestvk97few5vdx95cga9v5pf594gd984a5c3
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
