use-twenty-mcp
Pass
Audited by Gen Agent Trust Hub on Jun 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill enables connectivity to a Twenty workspace via the Model Context Protocol (MCP) to retrieve and format CRM data like companies, people, and opportunities. This functionality aligns with the stated purpose of the skill.- [SAFE]: No malicious patterns such as credential harvesting, data exfiltration to unauthorized third-party domains, or high-risk command execution were identified.- [SAFE]: The skill references vendor-specific domains and infrastructure (e.g., twenty.com) which are consistent with the author's identity and primary functionality.- [SAFE]: The skill exhibits an indirect prompt injection surface as it processes external CRM data. This is documented as follows:
- Ingestion points: CRM records, objects, fields, and workspace schema retrieved from the Twenty platform (SKILL.md).
- Boundary markers: No explicit delimiters for separating retrieved data from instructions were found in the provided text.
- Capability inventory: No executable code, subprocess spawning, or system-level modification capabilities were detected in the analyzed files.
- Sanitization: The analyzed files do not describe specific sanitization or filtering logic for the ingested CRM data.
Audit Metadata