Typesense

Security checks across malware telemetry and agentic risk

Overview

This Typesense skill is coherent, but it gives an agent authenticated power to change or delete search data through a broad proxy without explicit safety checks.

Install only if you are comfortable letting Membrane and the agent access your Typesense environment. Prefer a read-only or least-privilege Typesense key when possible, review any proposed POST, PUT, PATCH, or DELETE request before it runs, and revoke the Membrane connection when you no longer need it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly documents raw proxy requests with destructive methods like POST, PUT, PATCH, and DELETE, but provides no guardrails about confirmation, change review, or read-only defaults. In an agent context, this can normalize direct state-changing calls and increase the chance of accidental data modification or deletion in a live Typesense instance.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal