Cronfree

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Cronfree integration, but it gives agents broad authenticated API access with limited safety scoping.

Review before installing. Use it only with the intended Cronfree account, prefer discovered Membrane actions over raw proxy requests, and require explicit confirmation before creating, updating, deleting, or triggering scheduled workflows. Avoid sending personal or sensitive data through proxy requests unless it is necessary for the task.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly documents raw proxy requests to the external API without requiring confirmation, read-only defaults, or warning that these requests may modify or transmit sensitive data. Because proxy requests can perform arbitrary authenticated operations, an agent could execute destructive or privacy-impacting actions more easily than when constrained to vetted high-level actions.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal