affinity
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
@membranehq/clipackage from the NPM registry. This is the official command-line tool for the Membrane platform, which is the vendor of the skill, and is necessary for its core functionality. - [COMMAND_EXECUTION]: The instructions direct the agent to execute shell commands using the
membraneCLI. These commands are used to handle user authentication, establish secure connections to the Affinity API, and perform CRM operations like searching and creating records. - [INDIRECT_PROMPT_INJECTION]: The skill interacts with external data from the Affinity platform, such as person details, notes, and organization descriptions. This introduces a surface where malicious instructions could theoretically be embedded in the CRM data and processed by the agent.
- Ingestion points: Data returned from
membrane action run,membrane action list, andmembrane requestcommands (e.g., note content, organization names). - Boundary markers: No specific delimiters or instructions to ignore embedded content are provided in the skill body.
- Capability inventory: The skill possesses the ability to execute shell commands via the
membraneCLI and perform network operations through the Membrane proxy. - Sanitization: There is no evidence of explicit validation, filtering, or escaping of the data retrieved from the Affinity API before it is presented to the agent.
Audit Metadata