Zoho Bigin CRM

Security checks across malware telemetry and agentic risk

Overview

This Zoho Bigin skill is mostly purpose-aligned, but it needs review because it can access and change live CRM data while using broad activation wording and referencing a missing shell helper.

Install only if you trust the missing bigin.sh helper and know exactly where it will come from. Keep BIGIN_WRITE unset unless approving one specific CRM change, avoid raw API calls unless you review the endpoint and payload, and ensure the OAuth file is limited to the intended Bigin account and scopes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger description is broad enough to activate on many ordinary CRM-related requests, including generic terms like CRM, Deal, Contact, and Account. In a skill that can perform write operations against live business records, unintended invocation increases the chance that the agent selects this skill when the user did not explicitly intend to use Bigin, which can expose CRM data or lead to mistaken modifications if later user intent is misinterpreted.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal