Crowddev

Security checks across malware telemetry and agentic risk

Overview

This Crowd.dev skill is a legitimate integration, but it gives an agent broad authenticated power to change or delete Crowd.dev data without clear approval safeguards.

Install only if you trust Membrane and the connected Crowd.dev tenant. Use a least-privileged Crowd.dev account where possible, and require the agent to list exact IDs and get explicit approval before any create, update, delete, or raw proxy request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill documents destructive delete actions alongside routine actions without any guardrails, warning text, or requirement for explicit confirmation. In an agentic context, this increases the risk of accidental or overly broad deletion of organizations or members if the model selects those actions based on ambiguous user input.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal