managing-hubspot
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes bash scripts within its discovery and analysis phases. These scripts execute shell commands such as
curl,jq, anddateto interact with the HubSpot API and process data. - [EXTERNAL_DOWNLOADS]: The skill makes network requests to
https://api.hubapi.com. This is the official domain for HubSpot, a well-known CRM and marketing service. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted data from external sources.
- Ingestion points: CRM object data (contacts, deals, tickets), workflow names, and email campaign performance metrics retrieved in Phase 1 and Phase 2.
- Boundary markers: Absent. The skill does not provide the agent with specific delimiters or instructions to ignore potential commands embedded within the retrieved CRM data.
- Capability inventory: The agent has the capability to execute shell commands via the provided scripts and format output based on the data received.
- Sanitization: While JSON parsing is handled safely via
jq, there is no evidence of semantic sanitization or filtering of the content to prevent malicious instructions in the data from influencing agent behavior.
Audit Metadata