Is bratchenko/self-integration safe?
Yes. bratchenko/self-integration is safe to install. Oathe's behavioral security audit gave the self-integration skill by bratchenko a trust score of 82/100 with 5 findings (1 high).
https://github.com/openclaw/skills/tree/main/skills/bratchenko/self-integration
Is bratchenko/self-integration safe to install?
This skill provides legitimate functionality to connect with external services through the Membrane API, but has significant data sharing implications. While transparent about its capabilities and requirements, it concentrates high-privilege access to multiple services and sends data to a third-party provider.
What security issues were found in bratchenko/self-integration?
Category Scores
Findings (5)
HIGH Broad data sharing with third-party service -25 ▶
The skill sends user data to Membrane's API service and can connect to any external app including Slack, GitHub, Google Sheets, etc. While transparent, this creates significant data exposure.
MEDIUM High-privilege credential requirement -10 ▶
Requires MEMBRANE_TOKEN which is described as 'a high-privilege credential that can create connections and run actions across external apps'
MEDIUM Concentration of cross-service API access -20 ▶
The skill centralizes access to multiple external services which could be attractive to attackers and amplify the impact of credential compromise
LOW Indirect manipulation potential through API scope -15 ▶
While no direct prompt injection is present, the broad API capabilities could potentially be used to manipulate agent behavior indirectly
LOW Potential for unintended cross-service actions -10 ▶
The skill's broad scope could enable actions across multiple services without explicit per-action user consent
Should I install bratchenko/self-integration?
Oathe's verdict for bratchenko/self-integration is SAFE with a trust score of 82/100. Recommendation: Install with caution.