Leadgenius

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate LeadGenius connector, but it should be reviewed because it gives an agent broad authenticated ability to change or delete business data without clear built-in guardrails.

Install only if you trust Membrane and intend to connect it to LeadGenius. Use a least-privileged LeadGenius account where possible, review the exact action or API request before it runs, and require explicit confirmation for any create, update, delete, bulk-change, or outreach-related operation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description is broad enough to match many generic 'manage data' or 'automate workflows' requests, which can cause the agent to invoke this integration outside a clearly scoped LeadGenius intent. In a connected CRM/data environment, overbroad routing increases the chance of unnecessary access to customer data or unintended state-changing operations.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The documentation explicitly enables direct proxy requests with POST, PUT, PATCH, and DELETE but does not warn that these methods can modify or delete remote data. In an agent setting, this lowers the barrier to destructive actions and can lead to accidental record changes or deletions if the model chooses raw requests instead of safer, narrower actions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal