Continuum Security Slne

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real Membrane integration, but it gives an agent broad authenticated access to sensitive security-platform data with limited guardrails.

Install only if you trust Membrane and intend to let an agent operate on your Continuum Security/IriusRisk account. Use a least-privileged connection, verify the target service/domain before authenticating, and require the agent to show the exact action, endpoint, request body, and expected impact before any write, delete, admin, bulk, or proxy request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill explicitly documents running actions and raw proxy requests against a remote API without emphasizing that these operations can transmit sensitive data or modify live records. In an agent context, this increases the chance of unintended network access or state changes being performed without adequate user awareness or confirmation.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal