1Password

Security checks across malware telemetry and agentic risk

Overview

This is a real 1Password integration, but it gives an agent broad delegated access to very sensitive vault data without enough built-in safety guidance.

Install only if you are comfortable giving Membrane-backed agent workflows access to 1Password. Use the least-privileged connection available, understand how to revoke it, avoid raw proxy requests unless clearly necessary, and require explicit approval before any bulk secret read or vault item create, update, or delete operation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly documents raw proxy access to the 1Password API, including state-changing methods like POST, PUT, PATCH, and DELETE, without requiring confirmation safeguards or warning about sensitive secret exposure. In the context of a password manager, this increases the chance an agent could modify, delete, or exfiltrate vault contents through overly broad or under-reviewed requests.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal