Octoparse

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Octoparse integration, but it gives an agent broad authenticated access to an Octoparse account through Membrane without enough built-in scoping for raw API calls.

Install only if you are comfortable granting Membrane-mediated access to the intended Octoparse account. Prefer discovered Membrane actions over raw proxy requests, and require the agent to show the endpoint, method, request body, and expected account impact before any write, delete, export, subscription, or bulk automation action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly documents direct proxy requests to the Octoparse API, including arbitrary paths, methods, headers, and body data, but does not instruct the agent to confirm with the user before transmitting potentially sensitive data. In an agent setting, this can lead to unintended external data disclosure or actions against the user's Octoparse account without sufficiently explicit user awareness at execution time.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal