Smsbump

Security checks across malware telemetry and agentic risk

Overview

This SMSBump skill is a coherent integration, but it can make authenticated changes to marketing and customer data without clear confirmation guardrails.

Install only if you trust Membrane and are comfortable giving an agent delegated access to SMSBump. Prefer discovered/pre-built actions over raw proxy calls, use the least-privileged SMSBump account available, and require explicit approval before sending messages or creating, updating, or deleting campaigns, customer records, orders, or automations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly documents raw proxy requests with support for POST, PUT, PATCH, and DELETE, but does not require confirmation, validation, or warn about side effects. In an agent setting, this can enable unintended or overly broad data modification against the connected SMSBump account, especially if a model interprets ambiguous user requests aggressively.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal