skills/twentyhq/twenty/use-twenty-mcp/Gen Agent Trust Hub

use-twenty-mcp

Pass

Audited by Gen Agent Trust Hub on Jun 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill enables connectivity to a Twenty workspace via the Model Context Protocol (MCP) to retrieve and format CRM data like companies, people, and opportunities. This functionality aligns with the stated purpose of the skill.- [SAFE]: No malicious patterns such as credential harvesting, data exfiltration to unauthorized third-party domains, or high-risk command execution were identified.- [SAFE]: The skill references vendor-specific domains and infrastructure (e.g., twenty.com) which are consistent with the author's identity and primary functionality.- [SAFE]: The skill exhibits an indirect prompt injection surface as it processes external CRM data. This is documented as follows:
  • Ingestion points: CRM records, objects, fields, and workspace schema retrieved from the Twenty platform (SKILL.md).
  • Boundary markers: No explicit delimiters for separating retrieved data from instructions were found in the provided text.
  • Capability inventory: No executable code, subprocess spawning, or system-level modification capabilities were detected in the analyzed files.
  • Sanitization: The analyzed files do not describe specific sanitization or filtering logic for the ingested CRM data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 12, 2026, 08:29 PM
Security Audit — agent-trust-hub — use-twenty-mcp