Blend

Security checks across malware telemetry and agentic risk

Overview

This Blend integration is coherent, but it gives an agent broad authenticated ability to change Blend data without clear confirmation guardrails.

Install only if you trust the Membrane CLI and are comfortable giving an agent delegated access to your Blend account. Prefer discovered Membrane actions, use the least-privileged account available, and require explicit approval before any create, update, publish, or delete operation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill documents a generic proxy request mechanism that supports mutating HTTP methods like POST, PUT, PATCH, and DELETE without any explicit caution about side effects, confirmation requirements, or read-only defaults. In an agent context, this increases the chance of unintended record changes or deletions against the user's Blend-connected data, especially when the model falls back to raw API calls.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal