Duo Security
v1.0.0Duo Security integration. Manage data, records, and automate workflows. Use when the user wants to interact with Duo Security data.
⭐ 0· 26·0 current·0 all-time
byMembrane Dev@membranedev
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
The name/description (Duo Security integration) matches the instructions: use the Membrane CLI to create connections, run actions, and proxy Duo API requests. Nothing in the skill asks for unrelated cloud/provider credentials or capabilities.
Instruction Scope
SKILL.md only instructs using the Membrane CLI (login, connect, list actions, run actions, and proxy requests). It does not ask the agent to read local files, harvest env vars, or call endpoints outside Membrane/Duo workflows.
Install Mechanism
There is no install spec in the registry (instruction-only), but the document recommends installing @membranehq/cli via `npm install -g`. Installing a global npm package is expected for a CLI workflow but warrants standard caution: verify the package source and trustworthiness before installing globally.
Credentials
The skill declares no required env vars or secrets and explicitly advises letting Membrane handle credentials. No disproportionate credential requests are present.
Persistence & Privilege
The skill is not always-enabled, has no install-time code, and does not request persistent system-wide changes or access to other skills' configurations.
Assessment
This skill is instruction-only and delegates all Duo API access/auth to the Membrane service and CLI. Before installing or following the steps: (1) verify that @membranehq/cli on npm and getmembrane.com / the referenced GitHub repo are the official sources you trust, (2) be aware that `npm install -g` installs a global binary—only do this if you trust the package, (3) the workflow requires a Membrane account and browser-based login (credentials are handled server-side by Membrane), and (4) review Membrane's privacy/security docs to ensure you are comfortable with them acting as a proxy for your Duo data. If you prefer not to trust a third-party proxy, use Duo's official APIs/SDKs directly instead.Like a lobster shell, security has layers — review code before you run it.
latestvk976gxeasv03syg5p9ddtnnx0x847vhj
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
