Bilionis

Security checks across malware telemetry and agentic risk

Overview

This looks like a legitimate API integration, but it gives the agent broad authenticated proxy power, including write and delete methods, without clear confirmation guardrails.

Install only if you trust Membrane and intend to let an agent access this connected service. Prefer curated actions over raw proxy calls, review the exact endpoint and payload, require fresh confirmation before POST/PUT/PATCH/DELETE, and revoke the connection when no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly documents a generic proxy request capability that supports arbitrary paths and destructive HTTP methods (POST, PUT, PATCH, DELETE) without any safety guidance, scoping limits, or confirmation requirements. In an agent setting, this can enable unintended data modification, deletion, or broad data access if the model uses the proxy loosely or on ambiguous user requests.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal