espocrm

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the @membranehq/cli package from the public npm registry. This is a vendor-provided tool used for authentication and API management.
  • [COMMAND_EXECUTION]: The skill relies on executing various shell commands using the membrane CLI to manage connections, list actions, and run API requests against EspoCRM.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from an external CRM system, creating a vulnerability surface for indirect prompt injection attacks.
  • Ingestion points: CRM entities such as Leads, Tasks, Opportunities, and Accounts are retrieved from EspoCRM and processed in the agent context (e.g., in SKILL.md examples and via membrane action run).
  • Boundary markers: The instructions do not specify the use of delimiters or provide warnings to the agent to ignore instructions embedded within the retrieved CRM data.
  • Capability inventory: The skill has the capability to perform network requests and modify CRM data through membrane action run and membrane request commands.
  • Sanitization: There is no evidence of data sanitization or validation protocols for content retrieved from the CRM before it is presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 04:10 PM
Security Audit — agent-trust-hub — espocrm