Chatbot Builder

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate Chatbot Builder integration, but it gives an agent live authority to delete records, send messages, trigger flows, and make raw authenticated API requests without clear confirmation safeguards.

Install only if you trust Membrane and intend to let an agent operate on live Chatbot Builder data. Before allowing deletes, updates, text messages, flow sends, or non-GET proxy requests, require the agent to show the target connection, record IDs or recipients, exact inputs, and expected effect, then get explicit approval.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill advertises delete operations without any warning that they are destructive or that confirmation should be obtained before execution. In an agent setting, this increases the chance of accidental data loss if the model selects or suggests a delete action based on ambiguous user intent.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill lists actions for sending messages, adding tags, and triggering flows without any privacy, consent, or anti-spam warning. This can lead an agent to contact users or alter customer engagement state without verifying authorization, recipient correctness, or messaging consent obligations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal