espocrm
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the
@membranehq/clipackage from the public npm registry. This is a vendor-provided tool used for authentication and API management. - [COMMAND_EXECUTION]: The skill relies on executing various shell commands using the
membraneCLI to manage connections, list actions, and run API requests against EspoCRM. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from an external CRM system, creating a vulnerability surface for indirect prompt injection attacks.
- Ingestion points: CRM entities such as Leads, Tasks, Opportunities, and Accounts are retrieved from EspoCRM and processed in the agent context (e.g., in
SKILL.mdexamples and viamembrane action run). - Boundary markers: The instructions do not specify the use of delimiters or provide warnings to the agent to ignore instructions embedded within the retrieved CRM data.
- Capability inventory: The skill has the capability to perform network requests and modify CRM data through
membrane action runandmembrane requestcommands. - Sanitization: There is no evidence of data sanitization or validation protocols for content retrieved from the CRM before it is presented to the agent.
Audit Metadata