salesflare
Pass
Audited by Gen Agent Trust Hub on May 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Recommends installing the
@membranehq/clipackage from the NPM registry to interact with the Membrane platform. - [COMMAND_EXECUTION]: Uses the
membranecommand-line interface for operations such as logging in, connecting to the Salesflare connector, and running CRM actions. - [DATA_EXFILTRATION]: Accesses CRM data from Salesflare (contacts, opportunities, emails). The skill instructs the agent to use a server-side connection model which avoids local credential storage.
- [PROMPT_INJECTION]: The skill processes external data such as emails and tasks from Salesflare which may contain untrusted content.
- Ingestion points: Salesflare API (emails, tasks, contacts).
- Boundary markers: None specified in the instructions.
- Capability inventory: CLI subprocess execution via
membranecommands. - Sanitization: Not specified in the skill documentation.
Audit Metadata