Teamdeck

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Teamdeck integration that discloses its Membrane-based access, though it can act on Teamdeck business data after authorization.

Install only if you trust Membrane and intend to connect it to Teamdeck. Use a least-privilege Teamdeck account where possible, review the browser authorization flow, and require explicit confirmation before creating, updating, deleting, approving, or bulk-changing Teamdeck records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly documents raw proxy requests with GET, POST, PUT, PATCH, and DELETE but does not require confirmation or warn that these operations may modify or delete remote Teamdeck data. In an agent setting, this increases the chance of unintended destructive actions against production organizational records, especially when the skill also encourages direct API fallback when prebuilt actions are insufficient.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal