Localstack

Security checks across malware telemetry and agentic risk

Overview

This is a coherent LocalStack integration that uses Membrane CLI access, with a normal caution that raw API requests can change local cloud-emulated resources.

Install this only if you are comfortable using Membrane as the access path to LocalStack. Review generated commands before execution, especially raw proxy requests and non-GET methods, and revoke or log out of Membrane when you no longer want persistent delegated access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly documents raw proxy requests with arbitrary HTTP methods including POST, PUT, PATCH, and DELETE, but does not warn that these can alter or destroy LocalStack resources. In an agent context, this increases the chance that the model performs state-changing operations without clear user awareness or confirmation, especially because LocalStack often mirrors cloud-management workflows.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal