Weavr
v1.0.0Weavr integration. Manage data, records, and automate workflows. Use when the user wants to interact with Weavr data.
⭐ 0· 29·0 current·0 all-time
byMembrane Dev@membranedev
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
Capability signals
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
OpenClaw
Benign
high confidencePurpose & Capability
The name/description (Weavr integration) matches the SKILL.md content: all runtime steps involve installing/using the Membrane CLI to discover/connect to Weavr and run/proxy API actions. No unrelated services, env vars, or binaries are requested.
Instruction Scope
Instructions are limited to installing and using the Membrane CLI, logging in via browser, creating connections, listing actions, running actions, and proxying requests to the Weavr API. These steps are scoped to the stated purpose, but they imply that request payloads and credentials will be routed through Membrane's servers — users should be aware that data sent via 'membrane request' is proxied off-host.
Install Mechanism
There is no automated install spec in the skill (instruction-only). The doc recommends 'npm install -g @membranehq/cli' (and uses 'npx' elsewhere). This is a normal, low-risk instruction, but installing a global npm package requires trusting the package and its publisher.
Credentials
The skill declares no required env vars or credentials. It explicitly instructs the user not to provide API keys and instead create a connection so Membrane handles auth server-side. The requested access (network + Membrane account) is proportionate to the task.
Persistence & Privilege
The skill is not forced-always and does not request system persistence or access to other skills/config. Autonomous model invocation is allowed (platform default) and, by itself, does not raise concerns here.
Assessment
This skill is an instruction-only integration that asks you to use the official Membrane CLI to connect to Weavr. Before installing or using it: (1) verify you trust Membrane (getmembrane.com and the @membranehq npm package / GitHub repo) because authentication and proxied requests will traverse their service; (2) prefer using npx (as shown in the doc) if you want to avoid a global npm install; (3) never paste unrelated secrets or system credentials into the chat or into commands—only complete the interactive login for Membrane as directed; (4) if you need strict data residency or privacy, confirm that routing requests through Membrane is acceptable for your data; otherwise the skill appears internally consistent and suitable for the stated purpose.Like a lobster shell, security has layers — review code before you run it.
latestvk973t4qw7a0mnxbv9a51e7epax848w9b
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
