Shortio

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Short.io integration, but it gives an agent broad authenticated ability to act through Membrane, including write and delete API requests, without clear confirmation guardrails.

Install only if you intend to let an agent use your Short.io account through Membrane. Use a least-privileged Short.io account where possible, review the Membrane connection, and require the agent to show the exact action or API request before any POST, PUT, PATCH, DELETE, team, user, domain, or bundle change.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly requires network access and documents direct API/proxy requests, but it does not clearly instruct the agent to obtain or confirm user consent before transmitting potentially sensitive Short.io account data to external services. In an agent setting, this can lead to unintended data disclosure, especially when broad account-management operations or raw proxy requests are available.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal