pipedrive
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the Membrane CLI to perform various tasks such as listing connections, searching for actions, and executing Pipedrive API calls.- [EXTERNAL_DOWNLOADS]: Instructions include the installation of the
@membranehq/clipackage from the NPM registry, which is a resource provided by the vendor 'membranedev' for interacting with their services.- [PROMPT_INJECTION]: The skill processes external data from Pipedrive (deals, leads, and contacts), which serves as an ingestion point for untrusted content. While the skill lacks explicit boundary markers or sanitization logic in its instructions, this risk is inherent to the integration's primary purpose of processing CRM data.
Audit Metadata