Zuplo

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Zuplo administration skill that uses Membrane to connect to a Zuplo account, with powerful but purpose-aligned access.

Install only if you trust Membrane and intend to connect a Zuplo account. Prefer discovered Membrane actions, use a least-privilege Zuplo account when possible, and review the exact endpoint, HTTP method, and payload before allowing POST, PUT, PATCH, or DELETE requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description is broad enough to trigger on many generic requests about data, records, or workflows, which can cause the agent to select this skill outside a clearly intended Zuplo-management context. Overbroad routing increases the chance of unnecessary external actions or disclosure through an integration the user did not explicitly mean to use.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill documents raw proxying to arbitrary Zuplo API endpoints and explicitly lists mutating methods like POST, PUT, PATCH, and DELETE without requiring confirmation or warning about destructive effects. In an agent setting, this can enable unintended modification or deletion of gateway configuration, secrets, users, routes, or other production resources if the agent acts on ambiguous prompts.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal