Paubox

Security checks across malware telemetry and agentic risk

Overview

This Paubox skill is not malware, but it needs Review because it enables broad authenticated access to a healthcare email system without clear safeguards for changes or raw API requests.

Install only if you trust Membrane and intend to grant it delegated Paubox access. Use a least-privileged Paubox account, verify the Membrane CLI package before global installation, and require explicit approval before any send, create, update, delete, account, user, organization, bulk, or raw proxy operation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The skill description is broad enough to match generic requests about managing data or records, which can cause the agent to invoke this Paubox skill outside a clearly intended email/PHI context. Because Paubox is a HIPAA-related system, overbroad activation increases the chance of unnecessary access to sensitive healthcare data or unintended execution of actions against the wrong system.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The documentation encourages running actions and proxying raw API requests directly against a PHI-capable platform without warning about sensitivity, least privilege, user confirmation, or read-versus-write risk. In a healthcare context, this can lead to accidental disclosure, modification, or transmission of protected health information through broad or unsafe requests.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal