Parsioio

Security checks across malware telemetry and agentic risk

Overview

This is a real Parsio.io integration, but it gives an agent broad authenticated power to change business parsing data and user/account resources without clear approval boundaries.

Install only if you trust Membrane and need agent access to Parsio.io. Use the least-privileged Parsio account available, verify the Membrane CLI before global installation, and require explicit approval before the agent creates, edits, deletes, or manages documents, parsers, templates, folders, integrations, or users.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs the agent to use a generic proxy request mechanism to call the external Parsio.io API, but it does not warn that arbitrary request paths, headers, query parameters, and bodies may send user or system data to a third-party service. In an agent setting, this omission increases the risk of unintended data exfiltration or privacy violations because the agent may compose and transmit sensitive content without explicit user awareness or confirmation.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal