Commonpaper

Security checks across malware telemetry and agentic risk

Overview

This is a real Common Paper integration, but it gives an agent broad authenticated ability to read, modify, and delete sensitive contract records without clear confirmation guardrails.

Install only if you trust Membrane and the agent with the relevant Common Paper workspace. Prefer prebuilt read-only actions where possible, and require the agent to show the exact endpoint, method, and payload before creating, editing, sending, or deleting contract-related records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description is overly broad for a capability that can manage records and automate workflows against an external legal-contract platform. In agent-routing contexts, this can cause the skill to be selected for generic data-management requests and then operate on sensitive contract data without sufficiently clear user intent or scope boundaries.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The documentation explicitly enables direct proxy requests with GET, POST, PUT, PATCH, and DELETE but does not pair those capabilities with guardrails about destructive operations, user confirmation, or least-privilege usage. In a contracts platform context, this increases the chance of accidental or unauthorized modification, deletion, or disclosure of sensitive legal records.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal