freshsales

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the Membrane CLI tool (@membranehq/cli) from the official npm registry to facilitate communication with the Freshsales API.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the membrane CLI for tasks such as logging in, managing connections, and executing CRM actions.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection as it ingests data from external Freshsales records that could contain malicious instructions.
  • Ingestion points: Data retrieved from various CRM entities, such as Contacts, Leads, Deals, and Notes, through the membrane action run and membrane request commands.
  • Boundary markers: The instructions do not provide specific boundary markers or warnings to the agent to ignore instructions embedded within the CRM data.
  • Capability inventory: The skill has the capability to modify CRM data (create, update, delete) and perform arbitrary API requests through a proxy using membrane request.
  • Sanitization: There are no mentioned mechanisms for sanitizing, validating, or escaping the content retrieved from Freshsales before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:57 AM
Security Audit — agent-trust-hub — freshsales