activeprospect
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the official Membrane CLI tool (
@membranehq/cli) from the NPM registry. This is a standard procedure for using the platform's services. - [COMMAND_EXECUTION]: The skill uses the
membraneCLI to manage connections and run actions. These commands are scoped to the ActiveProspect integration and follow the principle of least privilege by using the platform's authentication management instead of raw API keys. - [DATA_EXFILTRATION]: No evidence of unauthorized data transfer. The skill documentation explicitly advises against asking users for API keys, recommending the use of managed connections to handle credentials securely.
- [PROMPT_INJECTION]: The instructions do not contain any patterns typical of prompt injection or attempts to bypass safety filters. The language is purely instructional and technical.
Audit Metadata