Ewebinar

Security checks across malware telemetry and agentic risk

Overview

The skill is a real EWebinar integration, but it gives an agent broad authenticated request power that can change account data or call arbitrary URLs.

Review before installing. Use it only if you trust Membrane-mediated access to your EWebinar account, prefer predefined Membrane actions, require explicit approval before create/update/delete requests, and avoid full-URL proxy requests unless the destination and data are clearly verified.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill exposes a generic proxy request feature that can send arbitrary requests, including full URLs and destructive methods like POST, PUT, PATCH, and DELETE, without any embedded guardrails or approval guidance. In an agent context, this increases the risk of SSRF-like outbound access, unintended data exfiltration, or destructive API operations against EWebinar or other destinations if the model follows ambiguous or adversarial prompts.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal