activecampaign

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli package from the npm registry. This is the official command-line interface for the Membrane platform, provided by the skill's author, and is used to manage service connections.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the membrane CLI to manage ActiveCampaign data, search for actions, and proxy HTTP requests. These commands are necessary for the skill's functionality and use the vendor's managed infrastructure for authentication.
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes data from external ActiveCampaign accounts (contacts, deals, tasks, etc.). While this data could theoretically contain malicious instructions, this represents a standard integration attack surface common to marketing automation tools and relies on the underlying agent's own safeguards.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 04:50 AM
Security Audit — agent-trust-hub — activecampaign