activecampaign-automation
Pass
Audited by Gen Agent Trust Hub on Feb 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
- [EXTERNAL_DOWNLOADS] (LOW): The skill directs users to add an external MCP server (https://rube.app/mcp) that is not on the trusted source list. This is the primary method of operation for the skill.- [INDIRECT_PROMPT_INJECTION] (LOW): The skill is susceptible to indirect prompt injection through data retrieved from ActiveCampaign contacts. * Ingestion points: Contact data returned by ACTIVE_CAMPAIGN_FIND_CONTACT. * Boundary markers: Absent; there are no instructions to isolate or verify external contact data. * Capability inventory: Write operations including contact creation, tagging, list management, and task generation. * Sanitization: Absent; the skill does not specify any validation or sanitization for ingested data.
Audit Metadata