agile-crm
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the @membranehq/cli package, which is the official CLI tool provided by the vendor (Membrane) for platform integration.
- [COMMAND_EXECUTION]: The instructions require the agent to execute shell commands using the membrane CLI to authenticate, manage connections, and interact with the Agile CRM API.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from Agile CRM, creating a potential vector for indirect prompt injection. 1. Ingestion points: Data retrieved via membrane action run and membrane request commands, such as contact notes or deal metadata. 2. Boundary markers: The skill does not provide delimiters or specific instructions to ignore content that might resemble commands within the ingested data. 3. Capability inventory: The agent can execute CLI commands that perform network requests and modify CRM data. 4. Sanitization: No explicit validation or sanitization of the CRM content is performed before the agent processes it.
Audit Metadata