Addevent

Security checks across malware telemetry and agentic risk

Overview

This looks like a legitimate Addevent integration, but it gives an agent broad authenticated ability to change or delete event data without enough safety guidance.

Install only if you trust Membrane and intend to let an agent operate on your Addevent account. Require explicit confirmation before create, update, delete, or non-GET proxy requests, and revoke the Membrane/Addevent connection when it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
80% confidence
Finding
The skill description is broad enough that an orchestrator could invoke it for loosely related requests involving Addevent data, increasing the chance of overbroad tool use. In a skill that can list, create, update, and delete records, ambiguous routing can lead to unnecessary access to external data or unintended side effects.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill advertises delete-event, delete-calendar, delete-calendar-subscriber, and delete-rsvp-attendee capabilities but provides no safety guidance around confirmation, dry runs, or scope verification. In an agent context, this omission raises the risk that a model may execute destructive actions from ambiguous or incomplete user instructions, causing data loss or service disruption.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal