pipedrive

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Membrane CLI to perform various tasks such as listing connections, searching for actions, and executing Pipedrive API calls.- [EXTERNAL_DOWNLOADS]: Instructions include the installation of the @membranehq/cli package from the NPM registry, which is a resource provided by the vendor 'membranedev' for interacting with their services.- [PROMPT_INJECTION]: The skill processes external data from Pipedrive (deals, leads, and contacts), which serves as an ingestion point for untrusted content. While the skill lacks explicit boundary markers or sanitization logic in its instructions, this risk is inherent to the integration's primary purpose of processing CRM data.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 04:52 PM
Security Audit — agent-trust-hub — pipedrive