activecampaign
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
@membranehq/clipackage from the npm registry. This is the official command-line interface for the Membrane platform, provided by the skill's author, and is used to manage service connections. - [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the
membraneCLI to manage ActiveCampaign data, search for actions, and proxy HTTP requests. These commands are necessary for the skill's functionality and use the vendor's managed infrastructure for authentication. - [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes data from external ActiveCampaign accounts (contacts, deals, tasks, etc.). While this data could theoretically contain malicious instructions, this represents a standard integration attack surface common to marketing automation tools and relies on the underlying agent's own safeguards.
Audit Metadata