Edapp

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate EdApp connector, but it can create, change, or delete account data without clear safety instructions.

Install only if you trust Membrane and want an agent to administer your EdApp account. Use the least-privileged EdApp account available, verify the exact Membrane connection and target records, require manual approval before create/update/delete or webhook changes, and revoke the Membrane connection when it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly documents destructive operations such as deleting users, groups, and webhooks without any guidance to require user confirmation, scope checks, or safe handling. In an agentic context, this increases the risk of accidental or overly broad destructive actions being executed against a live EdApp tenant.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal