Mend

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Mend integration, but it gives an agent broad Mend access through Membrane without clear guardrails for write, delete, or admin actions.

Install only if you are comfortable connecting Mend through Membrane. Use a least-privilege Mend account, review or pin the Membrane CLI version before global install, and require explicit approval before any write, delete, user, role, policy, workflow, ignore-rule, or API-key-related action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill description is overly broad ('Manage data, records, and automate workflows'), which could cause an agent to invoke this skill for generic enterprise-data tasks beyond Mend-specific security workflows. Because the skill enables authenticated network actions and proxy requests, accidental invocation could expose or modify external data in the wrong context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal