扫描报告
5 /100
ibm-cloud
IBM Cloud integration. Manage data, records, and automate workflows.
Purely documentation-based skill containing only SKILL.md that describes how to use the legitimate Membrane CLI for IBM Cloud integration. No executable code, scripts, or binary files present.
可以安装
No action required. The skill is a documentation wrapper with no attack surface.
| 资源类型 | 声明权限 | 推断权限 | 状态 | 证据 |
|---|---|---|---|---|
| 文件系统 | NONE | NONE | — | N/A - no code files |
| 网络访问 | NONE | READ | ✓ 一致 | SKILL.md contains URLs to Membrane and IBM Cloud docs (legitimate) |
| 命令执行 | NONE | NONE | — | SKILL.md documents npm/npx commands but contains no shell script execution |
| 环境变量 | NONE | NONE | — | No environment variable access in documentation |
| 技能调用 | NONE | NONE | — | No skill invocation documented |
| 剪贴板 | NONE | NONE | — | N/A |
| 浏览器 | NONE | NONE | — | SKILL.md mentions browser-based auth flow for Membrane login (legitimate OAuth p… |
| 数据库 | NONE | NONE | — | N/A |
2 项发现
中危 外部 URL 外部 URL
https://getmembrane.com SKILL.md:7 中危 外部 URL 外部 URL
https://cloud.ibm.com/docs SKILL.md:19 目录结构
1 文件 · 4.7 KB · 138 行 Markdown 1f · 138L
└─
SKILL.md
Markdown
安全亮点
✓ No executable code files - purely documentation
✓ Explicitly states 'never ask the user for API keys or tokens' - good security guidance
✓ Delegates credential management to Membrane (a known credential broker)
✓ No credential harvesting or exfiltration patterns
✓ No base64, obfuscation, or anti-analysis techniques
✓ Uses legitimate IBM Cloud and Membrane documentation URLs
✓ npm package @membranehq/cli is from a known publisher (Membrane HQ)