intercom

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli package from the NPM registry. This package is provided by the vendor (Membrane) to enable integration with their platform.- [COMMAND_EXECUTION]: The instructions direct the agent to execute several shell commands using the Membrane CLI, including membrane login, membrane connect, and membrane action run. These are used for authentication and interacting with the Intercom API.- [DATA_EXFILTRATION]: The skill's primary purpose is to read and manage data from Intercom (e.g., conversations, user profiles). This data is processed through Membrane's infrastructure as part of the integration's design.- [PROMPT_INJECTION]: The skill processes untrusted external data from Intercom, which constitutes an indirect prompt injection surface. Ingesting content from customer messages or help articles could allow third-party data to influence the agent's context or behavior.
  • Ingestion points: Intercom Conversations, Articles, User profiles, and Feedback Responses.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands within the ingested data are provided in the skill instructions.
  • Capability inventory: The skill possesses the ability to perform write operations (sending replies, updating records) via membrane action run and membrane request across several Intercom modules.
  • Sanitization: There are no explicit instructions for the agent to sanitize or validate the content retrieved from external Intercom sources before processing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 01:30 AM