Cookie Information

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Cookie Information integration that uses Membrane for authenticated account access, with some normal caution needed around write actions and raw API requests.

Install only if you are comfortable connecting Membrane to your Cookie Information account. Prefer discovered Membrane actions over raw proxy requests, confirm any update, scan-start, POST/PUT/PATCH/DELETE, or access to sensitive privacy records before running it, and consider pinning the Membrane CLI version in controlled environments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
82% confidence
Finding
The skill explicitly documents direct proxy requests and supports state-changing HTTP methods, but it does not instruct the agent to confirm destructive or privacy-impacting operations before execution. In a privacy/compliance platform, raw requests can expose, modify, or delete sensitive records, making undocumented guardrails risky.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal