skills/rustykuntz/rocie-tools/hubspot/Gen Agent Trust Hub

hubspot

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill uses official HubSpot API endpoints and follows standard authentication practices without any signs of malicious intent.
  • [COMMAND_EXECUTION]: Employs standard system tools curl and jq to perform network operations and process structured data.
  • [DATA_EXFILTRATION]: All network requests target api.hubapi.com, which is the official domain for HubSpot's well-known CRM services.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests data from external CRM objects.
  • Ingestion points: CRM object properties (contacts, deals, companies) fetched from api.hubapi.com in SKILL.md.
  • Boundary markers: None present in the instructions.
  • Capability inventory: Shell execution via curl and jq as documented in SKILL.md.
  • Sanitization: None identified in the provided file.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 07:46 PM
Security Audit — agent-trust-hub — hubspot