Svix

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Svix integration, but it gives broad authenticated API access that can change or delete Svix resources without clear confirmation safeguards.

Install only if you trust Membrane and the npm CLI package. Use a least-privileged Svix account when possible, review and revoke the Membrane connection when finished, and require the agent to confirm the exact target and impact before any create, update, delete, or raw proxy request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly documents a generic proxy mechanism that supports arbitrary API paths and mutating methods including DELETE, POST, PUT, and PATCH, but does not require confirmation, scope validation, or a read-only-first workflow. In an agent context, this increases the risk of unintended destructive actions against Svix resources, especially when the model is following high-level user requests or ambiguous prompts.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal