Akismet

Security checks across malware telemetry and agentic risk

Overview

This is a normal Akismet integration through Membrane, with disclosed network access and authentication, but users should review data sent through proxy requests.

Install this only if you trust Membrane as the gateway for Akismet. Prefer the listed Akismet actions, review any POST, PUT, PATCH, DELETE, or arbitrary proxy request before it runs, and avoid sending unnecessary personal data, comment content, IPs, emails, or unrelated secrets.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill description is broad enough to match generic 'manage data' or 'automate workflows' requests, which can cause the agent to invoke this Akismet skill outside a clearly spam-filtering context. Over-broad routing increases the chance of unnecessary external access, user-data transmission, or accidental actions against the wrong service.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The proxy request section instructs the agent to send direct requests to the Akismet API but does not warn that request paths, headers, query parameters, and bodies may contain sensitive user or site data. In this context, the skill is designed for networked external interaction, so missing disclosure and safety checks materially increase the risk of unintended data exfiltration or privacy violations.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal