Conversionomics

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Conversionomics integration, but it gives agents broad authenticated API access that can modify or delete business data without clear confirmation guidance.

Install only if you trust Membrane with the relevant Conversionomics account. Prefer curated Membrane actions first, and require explicit approval before any raw proxy request that creates, changes, or deletes data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs the agent to use a generic authenticated proxy for arbitrary API paths and supports all major HTTP methods, including potentially destructive ones like DELETE, PATCH, and POST, without requiring confirmation or warning about sensitive data transmission. In the context of a network-enabled integration skill, this meaningfully increases the chance of unsafe requests, data leakage, or unintended state-changing operations against the user's Conversionomics account.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal