Pidj

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Pidj integration, but it gives an agent broad authenticated ability to read and change Pidj business data through Membrane.

Install only if you trust Membrane and want an agent operating on Pidj data. Use a least-privileged Pidj account where possible, review connection scopes, and require confirmation before create, update, delete, or raw proxy requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill description is broad enough that an agent may invoke this skill for many loosely related requests involving people, organizations, projects, or generic business data. Over-broad routing increases the chance of unnecessary external data access or unintended actions in the wrong system, especially because the skill supports both action execution and raw proxy requests.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal