Lessonspace

Security checks across malware telemetry and agentic risk

Overview

This Lessonspace skill is a real integration, but it gives an agent broad authenticated Lessonspace control, including user deletion and raw API requests, without clear confirmation guardrails.

Install only if you trust Membrane and need this level of Lessonspace access. Use a least-privileged Lessonspace account where possible, confirm exact organisation and user IDs before deletion or updates, avoid raw proxy requests unless necessary, and revoke the Membrane connection when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill advertises a destructive 'Delete User' action without any warning, confirmation requirement, or guidance to verify authorization and target identity before execution. In an agent setting, that increases the chance of accidental or insufficiently reviewed destructive operations against real Lessonspace organization data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal