Questdb

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed QuestDB integration that relies on Membrane for authentication and API access, with no hidden executable behavior found.

Install only if you trust Membrane and intend to let an agent access QuestDB through it. Use least-privilege QuestDB access, consider pinning the Membrane CLI version instead of using @latest, and require explicit user approval before POST, PUT, PATCH, DELETE, schema changes, or raw proxy requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill description is broad enough that an agent may invoke it for generic database or data-management requests, even when the user did not specifically intend to use QuestDB or Membrane. Over-broad routing can cause unintended external actions, unnecessary connection setup, or data access attempts in the wrong system, which is a real security and safety issue for tool-selection logic.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal