1Msg

Security checks across malware telemetry and agentic risk

Overview

This is a coherent 1msg messaging integration that uses Membrane for account access, with some sensitive but expected messaging and raw API capabilities users should control carefully.

Install only if you trust Membrane and 1msg with the connected account data. Before using it, require the agent to show and confirm any outbound message, media send, profile update, webhook change, mutating API call, or raw proxy request, and revoke the Membrane connection when it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill encourages direct proxy requests to the 1msg API without explicitly warning that arbitrary request paths and payloads may send user or third-party messaging data over the network. In a messaging integration, this increases the chance an agent uses raw requests for sensitive content or metadata without clear user awareness or appropriate minimization.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal