Github

Security checks across malware telemetry and agentic risk

Overview

This is a real GitHub integration, but it gives an agent broad authenticated GitHub write and raw API capability without clear safety checks.

Install only if you trust Membrane and intend to grant GitHub access. Review the OAuth scopes, prefer least-privileged account or repository access, and require explicit confirmation before creating, updating, merging, releasing, deleting, or using non-GET proxy requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill advertises write-capable actions such as creating repositories, updating issues, creating releases, and merging pull requests without any warning or confirmation guidance for high-impact operations. In an agentic environment, this can enable unintended state-changing actions on user repositories if the agent interprets an ambiguous request too aggressively.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal