Jumpseller

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Jumpseller store integration, but it should be reviewed because it can change or delete live store data without clear safety checks.

Install only if you are comfortable letting an agent operate a Jumpseller store through Membrane. Prefer a test or least-privilege store connection, verify the Membrane CLI source before installing it globally, and require explicit confirmation for any create, update, delete, or non-GET proxy request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
82% confidence
Finding
The skill advertises destructive capabilities such as delete and update actions without any warning, confirmation requirements, or guardrails. In an agent setting, this increases the chance of unintended data loss or store modifications if the model selects these actions from ambiguous user requests or overly broad skill invocation.

VirusTotal

51/51 vendors flagged this skill as clean.

View on VirusTotal