Popupsmart
v1.0.2Popupsmart integration. Manage Popups, Integrations, Domains, Accounts. Use when the user wants to interact with Popupsmart data.
⭐ 0· 138·0 current·0 all-time
byMembrane Dev@membranedev
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description match the instructions: the SKILL.md explains how to manage Popupsmart via Membrane CLI and references official docs. No unexpected credentials, binaries, or paths are requested.
Instruction Scope
Instructions are scoped to using the Membrane CLI to discover connectors, create connections, run actions, and proxy API requests. They do not instruct reading local secrets, arbitrary system files, or transmitting unrelated data.
Install Mechanism
The skill is instruction-only (no install spec), but asks the user to install @membranehq/cli via npm -g. This is a standard third-party CLI install but carries the usual trust implications of installing global npm packages; the skill itself does not bundle or auto-install code.
Credentials
No environment variables or credentials are declared/required by the skill. The instructions explicitly say to let Membrane handle auth via its connection flow rather than asking for API keys locally.
Persistence & Privilege
always is false, no install spec and no code files — the skill does not request persistent system presence or elevated agent-wide privileges.
Assessment
This skill is an instructions-only integration that relies on the Membrane CLI and a Membrane account. Before using it: 1) Verify you trust the upstream Membrane project and review @membranehq/cli on npm and its GitHub repo; installing global npm packages has system-wide effects. 2) Understand that connecting requires authenticating in your browser (or using the headless flow) — you will not be asked to paste API keys into the skill. 3) Review Membrane's privacy/security docs to confirm how it proxies requests and stores connection credentials. 4) If you need stronger assurances, run the Membrane CLI commands manually in a controlled environment first to observe behavior (connection creation, action listing, proxy requests) before granting the agent permission to invoke the skill autonomously.Like a lobster shell, security has layers — review code before you run it.
latestvk973vmeccpp2empqwcm9vn07zn842d6g
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
