hubspot

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches and installs the Membrane CLI from the official npm registry. This is a vendor-provided tool required for the skill's functionality.
  • [COMMAND_EXECUTION]: Utilizes shell commands via the membrane CLI to authenticate, manage connections, and interact with the HubSpot API.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from HubSpot, such as contact names, company descriptions, and deal notes. If an attacker controls this data, it could potentially be used to deliver instructions to the agent.
  • Ingestion points: Output from membrane action run and membrane request commands (found in SKILL.md).
  • Boundary markers: The skill does not define specific delimiters for separating user-controlled HubSpot data from agent instructions.
  • Capability inventory: Includes the ability to execute shell commands (membrane CLI) and perform network operations.
  • Sanitization: No explicit instructions are provided for sanitizing or validating the content of records retrieved from HubSpot.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 04:08 PM
Security Audit — agent-trust-hub — hubspot