Inksprout
v1.0.2Inksprout integration. Manage Organizations, Pipelines, Users, Filters. Use when the user wants to interact with Inksprout data.
⭐ 0· 90·0 current·0 all-time
byMembrane Dev@membranedev
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
The name/description say 'Inksprout integration' and the runtime instructions only require the Membrane CLI, a Membrane account, and network access to connect to Inksprout — these are appropriate and expected for this purpose.
Instruction Scope
SKILL.md instructs installing the Membrane CLI, performing browser-based login, listing/creating connections, running actions, and proxying requests through Membrane. It does not ask the agent to read unrelated system files, local secrets, or network endpoints outside Membrane/Inksprout.
Install Mechanism
The skill is instruction-only (no automatic install). It recommends a user-run global npm install (@membranehq/cli). Global npm installs modify the system environment and pull code from the npm registry — verify the package name and provenance before installing.
Credentials
No environment variables or local credentials are requested. Authentication is done via Membrane's browser login/connection flow; this centralizes credentials server-side, which is proportionate but means you must trust Membrane to hold/manage access tokens.
Persistence & Privilege
The skill does not request permanent/always-on presence and does not modify other skills or global agent settings. The default ability for the agent to invoke the skill autonomously remains possible (platform default) but is not unique to this skill.
Assessment
This skill looks coherent, but before installing or using it: 1) Verify the @membranehq/cli package on the npm registry (correct author, download counts, repo link) before running a global npm install. 2) Understand that signing in ties your Membrane account to any connections you create — review Membrane's security/privacy and trust them to store API credentials. 3) Avoid pasting API keys or secrets into chat; use the browser login/connection flow as instructed. 4) If you are concerned about autonomous agent actions, limit the agent's permissions or only invoke the skill manually.Like a lobster shell, security has layers — review code before you run it.
latestvk979azxvmbkrn94y4w0wkb7tws8426nv
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
