Chatra

Security checks across malware telemetry and agentic risk

Overview

This is a real Chatra integration, but it gives an agent broad customer-data and messaging authority without clear confirmation safeguards.

Install only if you trust Membrane and need agent access to Chatra. Use a least-privileged Chatra account, confirm every send/edit/delete/update before it runs, and review exact endpoints, methods, and payloads before using raw proxy requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill description is broad enough that an agent could invoke it for loosely related requests about Chatra data without first establishing whether the user actually intends external-system access or modification. In a skill that can read, update, delete, and send messages to customer records, over-broad routing increases the chance of unintended data access or actions.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The documentation prominently includes destructive and state-changing actions such as delete, edit, send, and update, but it does not require confirmation, preview, or warn about irreversible effects. In a customer messaging platform, this can lead to accidental deletion of messages, unauthorized edits, or unintended outbound communications to clients.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal