Sms Partner

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed SMS Partner integration that uses Membrane for authenticated API access, with no hidden or malicious behavior found.

Install only if you intend to connect SMS Partner through Membrane. Review the account you authenticate, avoid placing unrelated private context into raw proxy requests, and require explicit approval before sending SMS messages or changing contact/account data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs the agent to send direct proxy requests to an external API without any warning about potential transmission of user, conversation, or system data off-platform. In an agent setting, this can lead to unintended exfiltration of sensitive data if the model constructs requests from ambient context or user-provided content without clear confirmation and data-minimization safeguards.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal