Pinecone

PassAudited by VirusTotal on Apr 30, 2026.

Findings (1)

The skill instructs the AI agent to perform high-risk operations including installing a global NPM package (`@membranehq/cli`) and routing all Pinecone database traffic and authentication through a third-party proxy service (`getmembrane.com`). While these actions are aligned with the stated purpose of using the Membrane platform, they introduce significant supply-chain risks and potential data exposure by intercepting sensitive API interactions. (SKILL.md)