Assembled

Security checks across malware telemetry and agentic risk

Overview

This looks like a legitimate Assembled integration, but it exposes broad authenticated API access that could modify tenant data without clear confirmation guardrails.

Install only if you trust the publisher and are comfortable giving the agent Membrane-mediated access to your Assembled tenant. Before using it, require the agent to prefer read-only/prebuilt actions, show the exact endpoint and payload, and get explicit confirmation before any create, update, delete, scheduling, workflow, or configuration change.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly documents a generic authenticated proxy that supports POST, PUT, PATCH, and DELETE without any guardrails, warnings, or confirmation requirements for state-changing requests. In an agent setting, this increases the risk of accidental or prompt-induced destructive actions against the Assembled tenant, especially when the model falls back to raw requests instead of curated actions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal