Dingconnect

Security checks across malware telemetry and agentic risk

Overview

This looks like a legitimate DingConnect integration, but it gives an agent broad authenticated ability to change customer and business data without clear safety guardrails.

Install only if you trust Membrane and intend an agent to operate on your DingConnect account. Use the least-privileged account available, review the DingConnect permissions granted, and require explicit approval before sending messages, editing records, changing billing or subscriptions, changing settings, running bulk operations, or using raw mutating proxy requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly documents raw proxy requests with support for mutating methods including POST, PUT, PATCH, and DELETE, but provides no guardrails around confirmation, least privilege, or destructive operations. In an agent setting, this increases the risk of unintended data modification or deletion if the model selects direct API access without user awareness.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal