Digistore24

Security checks across malware telemetry and agentic risk

Overview

This is a real Digistore24 integration, but it gives an agent broad commerce-account powers such as refunds, product deletion, customer-data access, and raw API requests without clear confirmation safeguards.

Install only if you trust Membrane and are comfortable granting delegated access to a live Digistore24 account. Use the least-privileged account available, require clear confirmation before refunds, deletes, creates, updates, or raw proxy requests, and revoke the Membrane/Digistore24 connection when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly documents destructive operations such as deleting products and refunding purchases but provides no guidance to require user confirmation, authorization checks, or clear warnings before execution. In an agent setting, this increases the chance of accidental or overly autonomous execution of irreversible or financially impactful actions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal