Cliengo

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Cliengo integration, but it gives an agent broad authenticated CRM powers without clear confirmation safeguards.

Install only if you trust Membrane and intend to let an agent operate inside your Cliengo account. Use the least-privileged account available, review the global CLI install, and require explicit confirmation before changing records, deleting contacts, managing users/sites, sending messages, or using raw proxy requests with non-GET methods.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill advertises create, update, delete, and message-sending actions without any nearby warning to require user confirmation before destructive or externally visible changes. In an agent setting, this can increase the chance of unintended record modification, deletion, or outbound communication if the model overgeneralizes from vague user requests.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal