Mindbody

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Mindbody integration, but it gives broad authenticated access that can change or delete business records without clear built-in confirmation guidance.

Install only if you trust Membrane and the npm CLI package, connect the least-privileged Mindbody account available, and require the agent to ask before creating, updating, deleting, or sending raw API requests. Revoke the Membrane/Mindbody connection when it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly advertises create, update, delete, and list operations on Mindbody records but does not instruct the agent to confirm destructive actions with the user or warn about data integrity risks. In an agent context, this omission can lead to accidental record modification or deletion if the model acts on ambiguous requests or overreaches.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The proxy-request section enables arbitrary API calls with custom methods, headers, body, and parameters, but provides no warning that such requests may exfiltrate data or perform irreversible mutations. Because this bypasses safer pre-built actions and gives broad request construction capability, an agent could unintentionally issue dangerous calls against production Mindbody resources.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal