Trusted — Risk Score 5/100
Last scan:2 days ago Rescan
5 /100
time-doctor
Time Doctor integration. Manage data, records, and automate workflows. Use when the user wants to interact with Time Doctor data.
Documentation-only skill that describes legitimate Time Doctor API integration via the Membrane CLI, with no implementation code, no hidden functionality, and no security risks.
Skill Nametime-doctor
Duration21.4s
Enginepi
Safe to install
This skill is safe to use. It contains only documentation for a legitimate API integration tool with no executable code or suspicious behavior.
2 findings
🔗
Medium External URL 外部 URL
https://getmembrane.com
SKILL.md:7
🔗
Medium External URL 外部 URL
https://www.timedoctor.com/api/
SKILL.md:19

File Tree

1 files · 4.4 KB · 127 lines
Markdown 1f · 127L
└─ 📝 SKILL.md Markdown 127L · 4.4 KB

Security Positives

✓ Documentation-only skill with no executable code
✓ No credential harvesting — explicitly instructs to use Membrane for auth lifecycle
✓ No sensitive path access (no ~/.ssh, ~/.aws, .env references)
✓ No network requests to suspicious endpoints
✓ No data exfiltration behavior
✓ Documented commands (npm install, membrane CLI) are appropriate for an API integration skill
✓ Explicitly warns against asking users for API keys or tokens
✓ References legitimate, well-known services (Membrane, Time Doctor API)