Affinity

Security checks across malware telemetry and agentic risk

Overview

This Affinity CRM skill is coherent but should be reviewed because it can create or update live business records through a persistent Membrane connection without clear confirmation boundaries.

Install only if you trust Membrane and the npm CLI package, use a least-privileged Affinity account, and require explicit review before creating or updating records. Revoke the Membrane/Affinity connection when it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
75% confidence
Finding
The invocation description is broad enough that an agent may activate this skill for loosely related Affinity requests without strong scope boundaries. In a network-enabled CRM integration, over-broad routing can lead to unintended access, querying, or modification of sensitive business records when the wrong tool is selected.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The skill documents search, retrieval, creation, and update actions against a live CRM but does not clearly warn that these operations transmit data over the network and may create or modify records. In this context, users or agents may invoke write-capable actions without appreciating the external side effects, increasing the risk of unauthorized or accidental data changes.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal