Plasmic

Security checks across malware telemetry and agentic risk

Overview

This Plasmic skill is a coherent integration, but it gives an authenticated agent broad API access that could change or delete Plasmic data without clear confirmation guardrails.

Install only if you are comfortable connecting Plasmic through Membrane. Use a least-privileged Plasmic account where possible, verify the Membrane CLI/package before installing, and require explicit approval before any write, publish, or delete request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly documents a generic proxy mechanism for arbitrary API requests to Plasmic, including support for state-changing HTTP methods like POST, PUT, PATCH, and DELETE, without requiring confirmation or warning about destructive operations. In an agent context, this expands capability from constrained prebuilt actions to effectively broad authenticated API access, increasing the risk of unintended modification, deletion, or exfiltration of remote data.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal