Simvoly

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Simvoly integration that uses Membrane for authenticated API access, with one documented raw-request fallback users should handle carefully.

Install this only if you want your agent to access and manage Simvoly through Membrane. Prefer listed Membrane actions over raw proxy requests, and require a clear user confirmation before any write or delete operation against websites, stores, memberships, forms, or customer data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill explicitly documents a generic proxy request mechanism supporting POST, PUT, PATCH, and DELETE without any corresponding warning or guardrail about destructive operations. In an agent setting, this increases the chance that the model may issue raw state-changing API calls against Simvoly resources, potentially modifying or deleting websites, stores, forms, or membership data without clear user intent verification.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal