activeprospect

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the official Membrane CLI tool (@membranehq/cli) from the NPM registry. This is a standard procedure for using the platform's services.
  • [COMMAND_EXECUTION]: The skill uses the membrane CLI to manage connections and run actions. These commands are scoped to the ActiveProspect integration and follow the principle of least privilege by using the platform's authentication management instead of raw API keys.
  • [DATA_EXFILTRATION]: No evidence of unauthorized data transfer. The skill documentation explicitly advises against asking users for API keys, recommending the use of managed connections to handle credentials securely.
  • [PROMPT_INJECTION]: The instructions do not contain any patterns typical of prompt injection or attempts to bypass safety filters. The language is purely instructional and technical.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 02:47 AM
Security Audit — agent-trust-hub — activeprospect