Gender Api

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Gender API integration, but it should be used carefully because it sends names or email-derived names to infer sensitive demographic traits.

Install only if you are comfortable sending names or email-derived names through Membrane to Gender API. Avoid using inferred gender, ethnicity, or origin for employment, housing, credit, insurance, eligibility, or other high-impact decisions, and get explicit user approval before batch lookups or raw proxy requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly promotes gender inference, demographic analysis, and personalization use cases without any warning that these are sensitive inferences about personal data. In practice, this can encourage processing of inferred gender or ethnicity-like attributes without user awareness, consent checks, or limitations, increasing privacy, fairness, and misuse risk.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal