Contentful

Security checks across malware telemetry and agentic risk

Overview

This Contentful skill is coherent, but it gives an agent broad CMS-changing powers without explicit safeguards for destructive or public-facing actions.

Install only if you trust Membrane as an intermediary for Contentful access. Use the least-privileged Contentful account or space possible, review the permissions during connection, and require explicit confirmation of the exact space, environment, entry, asset, and operation before allowing publish, unpublish, update, delete, or raw proxy requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill enumerates destructive actions such as delete and unpublish operations but provides no guidance to require explicit user confirmation, preview scope, or verify target resources before execution. In an agent setting, this increases the chance of accidental destructive changes to production CMS content, especially if the model infers user intent too broadly or acts on ambiguous instructions.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal