zoho-recruit

Pass

Audited by Gen Agent Trust Hub on May 2, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the @membranehq/cli package from the NPM registry. This is the official command-line interface for the Membrane platform and is maintained by the vendor.
  • [COMMAND_EXECUTION]: Utilizes the membrane CLI to manage connections and execute actions. These commands are used for legitimate integration purposes such as logging in, searching for API actions, and running them.
  • [PROMPT_INJECTION]: The skill processes external data from Zoho Recruit, which creates an inherent surface for indirect prompt injection.
  • Ingestion points: External record data retrieved via the membrane action run command.
  • Boundary markers: None defined in the instructions.
  • Capability inventory: Execution of API actions via membrane action run and dynamic action creation via membrane action create.
  • Sanitization: Relies on the underlying Membrane platform's handling of API inputs and outputs.
  • [SAFE]: The skill follows security best practices by explicitly instructing the agent not to handle or request raw API keys or tokens, instead utilizing a centralized authentication system.
Audit Metadata
Risk Level
SAFE
Analyzed
May 2, 2026, 04:01 AM