This appears to be a legitimate Membrane-powered Graphy integration, but it gives broad authenticated API access with unclear scope and weak safety guidance.
Install only if you trust Membrane and intend to let an agent operate on the connected Graphy account. Use the least-privileged account available, review the connection permissions, prefer listed read-only actions, and require explicit approval before any POST, PUT, PATCH, DELETE, purchase-related, user/account, order/payment, or course/product-changing operation. The pending VirusTotal result is not enough by itself to change the verdict, and static scan found no executable or suspicious patterns.