Cloud Elements

Security checks across malware telemetry and agentic risk

Overview

This looks like a legitimate Cloud Elements integration, but it gives an agent broad authenticated power to change business data without clear confirmation rules.

Install only if you trust Membrane and intend to grant broad Cloud Elements access. Use a least-privilege account or tenant, prefer discovered actions over raw proxy requests, and require the agent to show the endpoint, method, and request body before any create, update, delete, workflow, schedule, user, organization, or proxy operation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill explicitly documents a generic proxy request capability supporting POST, PUT, PATCH, and DELETE against the Cloud Elements API, but it does not require confirmation or warn about destructive effects. In an agent context, this increases the chance that the model may perform state-changing operations on production integrations, records, or workflows without adequate user awareness.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal