Back to skill

Security audit

dropbox-business

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Dropbox Business admin integration with powerful account access, but its behavior is coherent with that purpose and includes clear approval and credential-handling rules.

Install only if you intend to grant Dropbox Business admin-level access through Maton. Use the least-privileged Dropbox admin account available, review OAuth scopes before authorizing, prefer OAuth over API keys, and require explicit confirmation before any account, sharing, device, member-file, or deletion action.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.