lemlist

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the @membranehq/cli package from the public NPM registry. This tool is the primary interface for the skill's functionality and is a resource provided by the skill's authoring organization.
  • [COMMAND_EXECUTION]: The skill relies on executing the membrane command-line utility to manage Lemlist connections, search for available actions, and perform API requests. These commands are part of the intended integration workflow.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface where user-supplied natural language intents and structured JSON parameters are passed into CLI commands to interact with the Lemlist API.
  • Ingestion points: User-provided query strings for action discovery and input objects for action execution.
  • Boundary markers: None explicitly defined in the prompt templates.
  • Capability inventory: The skill can perform network operations and API requests through the Membrane proxy service.
  • Sanitization: Relies on the underlying CLI and backend service to validate inputs before transmission to the Lemlist API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:01 PM
Security Audit — agent-trust-hub — lemlist