Pipeline Crm

Security checks across malware telemetry and agentic risk

Overview

This is a real PipelineCRM connector, but it gives broad live CRM authority without enough built-in limits for sensitive or modifying actions.

Install only if you intend to let an agent use your PipelineCRM account through Membrane. Before use, require explicit confirmation for create, update, delete, payment, refund, campaign, social post, workflow, raw proxy, or bulk operations, and revoke the Membrane connection when it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description is broad enough to match many generic CRM-related requests, which increases the chance the agent invokes this skill in situations the user did not specifically intend. Because this skill can connect to remote systems and manage records/workflows, overbroad triggering can lead to unnecessary data exposure or unintended remote actions.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The description does not clearly warn that the skill performs networked operations against a live CRM and may create, update, or delete remote business data. That omission can cause users or orchestrators to treat it like a read-only informational skill, increasing the risk of unintended data modification or external data transmission.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal