247

Security checks across malware telemetry and agentic risk

Overview

This looks like a legitimate [24]7.ai integration, but it gives an agent broad authenticated API access without enough guardrails for write or delete actions.

Install only if you trust Membrane and need agent access to [24]7.ai. Use least-privilege [24]7.ai/Membrane permissions, prefer listed Membrane actions over raw proxy requests, and require clear confirmation before any write, delete, workflow, or bulk data operation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
81% confidence
Finding
The proxy request section instructs the agent to send direct API requests through Membrane but does not warn that arbitrary paths, headers, query parameters, and bodies may transmit sensitive user or enterprise data to an external service. In a skill that manages records and workflows, this omission increases the risk of unintended data disclosure or destructive API calls if an agent acts without explicit user awareness or confirmation.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal