Helpdocs

Security checks across malware telemetry and agentic risk

Overview

This HelpDocs skill is coherent and not malicious, but it gives an agent broad authenticated ability to change or delete HelpDocs content without clear confirmation or scoping rules.

Install only if you trust Membrane and want an agent to access your HelpDocs account. Use the least-privileged HelpDocs account available, require the agent to show the exact action or API request before any create, update, or delete operation, and revoke the Membrane connection when the work is done.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill exposes a generic authenticated proxy request mechanism without an explicit warning or guardrail around write-capable endpoints. That makes it easier for an agent to perform arbitrary POST/PUT/PATCH/DELETE operations against HelpDocs, including destructive changes, even when safer prebuilt actions or user confirmation should be used.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal