21Risk

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Membrane-based 21RISK connector, but it can act on live risk and compliance data once an account is connected.

Install this only if you trust Membrane and want an agent to work with your 21RISK tenant. Use a least-privileged account where possible, verify the tenant before connecting, and require explicit approval before any create, update, delete, settings, user-management, or bulk workflow action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The invocation condition is broad enough that an agent may select this skill for loosely related requests involving 21RISK data or workflow automation, increasing the chance of unintended access to sensitive risk/compliance records or accidental state-changing operations. In a skill that can authenticate to a live SaaS platform and run actions or proxy API requests, over-broad routing materially raises the risk of misuse.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The documentation encourages direct proxy requests to the 21RISK API and lists mutating HTTP methods like POST, PUT, PATCH, and DELETE without warning that these can alter or delete remote risk/compliance data. Because Membrane injects authentication automatically, an agent could perform impactful writes against production data with little friction if it misinterprets the user's intent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal