zoho-people
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on the
membraneCLI to perform operations such as authentication, connection management, and executing Zoho People actions from the terminal.- [EXTERNAL_DOWNLOADS]: Recommends the installation of the@membranehq/clipackage from the official NPM registry to provide the necessary tooling for the integration.- [PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it retrieves and processes untrusted data from Zoho People records. - Ingestion points: Results from
membrane action runwhich contain data from Zoho People forms and records. - Boundary markers: Not specified in the instructions.
- Capability inventory: The agent can execute shell commands via the
membraneCLI and dynamically create new actions. - Sanitization: No explicit sanitization or validation of the retrieved data is mentioned before processing.
Audit Metadata