Goto Webinar

Security checks across malware telemetry and agentic risk

Overview

This GoTo Webinar skill is coherent, but it enables real webinar changes and cancellations without clear confirmation guardrails.

Install only if you trust Membrane and are comfortable granting delegated access to GoTo Webinar. Before any create, update, delete, or cancel action, verify the exact webinar, registrant, panelist, or organizer target and require explicit confirmation; revoke the Membrane connection when it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
79% confidence
Finding
The skill advertises destructive operations such as deleting registrants, panelists, co-organizers, and canceling webinars without any guidance to require user confirmation for high-impact actions. In an agentic setting, this increases the risk that a loosely prompted or misrouted agent performs irreversible changes to production webinar data.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal