Gtmetrix

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed GTmetrix integration, but it can use a connected account to run tests and delete GTmetrix pages or reports.

Install only if you are comfortable using Membrane to access your GTmetrix account. Verify the Membrane CLI source, connect only the intended GTmetrix account, and require explicit confirmation before deleting pages/reports or running tests that may consume account credits.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly exposes destructive actions such as deleting pages and reports but provides no guidance to require user confirmation, dry-run behavior, or safeguards before execution. In an agent setting, this increases the risk that a misunderstood prompt or over-eager automation could permanently remove GTmetrix data without clear user intent.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal