close-automation
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires connecting to an external MCP server at
https://rube.app/mcp. This server provides the necessary tools to interface with the Close CRM API.\n- [PROMPT_INJECTION]: The skill processes data from the CRM and possesses capabilities to modify or delete records, creating an indirect prompt injection surface. This is inherent to its function as an automation tool.\n - Ingestion points: Data retrieved from Close CRM via tool calls such as
CLOSE_GET_NOTEor lead searches.\n - Boundary markers: The instructions do not specify the use of delimiters or 'ignore instructions' warnings when processing retrieved CRM content.\n
- Capability inventory: The skill uses tools including
CLOSE_CREATE_SMS,CLOSE_CREATE_CALL, andCLOSE_DELETE_CALL.\n - Sanitization: No explicit sanitization or validation steps are provided for the data fetched from the CRM before it is processed by the agent.
Audit Metadata