Zoho Creator

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Zoho Creator integration that can change or delete real business records, so it should be used with explicit user approval for destructive actions.

Install only if you trust Membrane and are comfortable authorizing Zoho Creator access through it. Use a least-privileged Zoho account, review granted scopes, and require explicit confirmation with narrow filters or record IDs before updates, deletes, bulk exports, user changes, role changes, or raw proxy requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
81% confidence
Finding
The skill prominently exposes destructive capabilities such as deleting records without adjacent warnings, confirmation requirements, or safety guidance. In an agent setting, that increases the chance of accidental or over-broad data deletion if the model chooses a destructive action based on ambiguous user input.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal