Appcues

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Appcues integration, but it can make real Appcues changes if connected with broad permissions.

Install only if you intend to let an agent work with your Appcues account through Membrane. Use least-privileged credentials, check the account and scopes before connecting, and ask the agent to preview changes before deleting profiles or segments, publishing flows, or using raw proxy requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
77% confidence
Finding
The documentation prominently lists destructive operations such as deleting user profiles, deleting segments, and publishing or unpublishing flows without any caution about confirmation, authorization, or irreversible effects. In an agent setting, this increases the chance that an LLM will select and execute high-impact actions without adequate user confirmation, potentially causing data loss or service disruption.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal