zoho-recruit
Pass
Audited by Gen Agent Trust Hub on May 2, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the
@membranehq/clipackage from the NPM registry. This is the official command-line interface for the Membrane platform and is maintained by the vendor. - [COMMAND_EXECUTION]: Utilizes the
membraneCLI to manage connections and execute actions. These commands are used for legitimate integration purposes such as logging in, searching for API actions, and running them. - [PROMPT_INJECTION]: The skill processes external data from Zoho Recruit, which creates an inherent surface for indirect prompt injection.
- Ingestion points: External record data retrieved via the
membrane action runcommand. - Boundary markers: None defined in the instructions.
- Capability inventory: Execution of API actions via
membrane action runand dynamic action creation viamembrane action create. - Sanitization: Relies on the underlying Membrane platform's handling of API inputs and outputs.
- [SAFE]: The skill follows security best practices by explicitly instructing the agent not to handle or request raw API keys or tokens, instead utilizing a centralized authentication system.
Audit Metadata