Amazon Eventbridge

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Amazon EventBridge integration, but it gives an agent broad authenticated AWS API power without clear safeguards for write or delete actions.

Install only if you are comfortable letting Membrane mediate access to your AWS EventBridge environment. Use least-privilege AWS credentials, prefer listed Membrane actions over raw proxy requests, and manually review any command that creates, updates, or deletes EventBridge resources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly documents direct proxy requests with state-changing HTTP methods like POST, PUT, PATCH, and DELETE, but does not warn that these calls can create, modify, or delete EventBridge resources. In an agent context, this increases the chance that the model performs destructive actions through a low-level interface without adequate user confirmation or safety guardrails.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal