Agent skill · security · membranedev
whitesource
WhiteSource integration. Manage data, records, and automate workflows. Use when the user wants to interact with WhiteSource data.
Why this skill is useful
Adds specific commands and workflows for integrating with WhiteSource that the AI wouldn't reliably generate on its own.
What it needs
Requires @membranehq/cli installed locally. Requires membrane account access. About 4k tokens when loaded. Last updated 2026-04-28. 253 stars on the source repository.
What this skill does
WhiteSource WhiteSource, now Mend, is a software composition analysis tool. It helps developers and security teams manage open source security and compliance risks in their software. It's used by organizations looking to automate the process of identifying and remediating vulnerabilities in open source components. Official docs: https://whitesource.atlassian.net/wiki/spaces/WD/overview WhiteSource Overview Alert Alert Assignment Project Project Token Product Organization User Report Inventory License Vulnerability Request Remediation File Working with WhiteSource This skill uses the Membrane CLI to interact with WhiteSource. Membrane handles authentication and credentials refresh automatically — so you can focus on the integration logic rather than auth plumbing. Install the CLI Install the Membrane CLI so you can run membrane from the terminal: Authentication This will either open a browser for authentication or print an authorization URL to the console, depending on whether interactive mode is available. Headless environments: The command will print an authorization URL. Ask the user to open it in a browser. When they see a code after completing login, finish with: Add --json to any command for machine-readable JSON output. Agent Types : claude, openclaw, codex, warp, windsurf, etc. Those will be used to adjust tooling to be used best with your harness Connecting to WhiteSource Use membrane connection ensure to find or create a connection by app URL or domain: The user completes authentication in the browser. The output contains the new connection id. This is the fastest way to get a connection. The URL is normalized to a domain and matched against known apps. If no app is found, one is created and a connector is built automatically. If the returned connection has state: "READY", skip to Step 2. 1b. …
How to use it
Reference it in AdaL, Claude Code, Cursor or any coding agent — nothing to install:
@skills membranedev/whitesource