Bugsnag

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Bugsnag integration that uses Membrane for authenticated API access; its main risk is that it can perform write and delete actions if the connected account permits them.

Install only if you trust Membrane with the Bugsnag organizations and projects you connect. Use the least-privileged Bugsnag account practical, verify resource IDs with read-only list/get actions first, and require explicit confirmation before updates, error deletion, or project deletion.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
78% confidence
Finding
The skill advertises destructive operations like deleting errors and projects without any warning, confirmation requirement, or guidance to verify user intent. In an agent context, this increases the chance that an LLM may invoke irreversible actions from ambiguous prompts, causing data loss or service disruption.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal