Sellhack

Security checks across malware telemetry and agentic risk

Overview

This SellHack skill appears legitimate, but it needs review because it enables broad authenticated API requests that could read, change, or delete contact data without clear safeguards.

Review before installing. Use it only with a SellHack account you intend the agent to access, prefer discovered Membrane actions over raw proxy requests, and require explicit user confirmation before creating, updating, deleting, exporting, or querying large volumes of contact data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly encourages direct proxy/API requests to SellHack without any privacy, data-minimization, or consent guidance, even though the platform handles prospect emails and contact information. In practice, this can lead an agent to transmit personal or sensitive lead data over the network in ways the user did not clearly authorize or that exceed least-privilege expectations.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal