freshsales
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the Membrane CLI tool (
@membranehq/cli) from the official npm registry to facilitate communication with the Freshsales API. - [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the
membraneCLI for tasks such as logging in, managing connections, and executing CRM actions. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection as it ingests data from external Freshsales records that could contain malicious instructions.
- Ingestion points: Data retrieved from various CRM entities, such as Contacts, Leads, Deals, and Notes, through the
membrane action runandmembrane requestcommands. - Boundary markers: The instructions do not provide specific boundary markers or warnings to the agent to ignore instructions embedded within the CRM data.
- Capability inventory: The skill has the capability to modify CRM data (create, update, delete) and perform arbitrary API requests through a proxy using
membrane request. - Sanitization: There are no mentioned mechanisms for sanitizing, validating, or escaping the content retrieved from Freshsales before it is processed by the agent.
Audit Metadata