Abstract

Security checks across malware telemetry and agentic risk

Overview

This Abstract integration is not deceptive, but it gives an agent broad authenticated power to read, change, or delete Abstract data without clear confirmation guardrails.

Install only if you trust Membrane and want an agent to operate your Abstract workspace. Use a least-privileged Abstract account where possible, require explicit approval before create, update, delete, or bulk actions, and revoke the Membrane connection when no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is overly broad: phrases like 'manage data, records, and automate workflows' can match many generic user requests and cause the skill to be selected outside its intended Abstract-specific context. Over-broad routing increases the chance of unintended external actions or data access being invoked when the user did not clearly ask to interact with Abstract.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The proxy-request section enables direct API calls, including mutating methods such as POST, PUT, PATCH, and DELETE, but does not warn that these operations can change or delete remote data. Without explicit safety guidance, an agent may perform destructive or privacy-impacting API requests with insufficient user confirmation.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal