Persistiq

Security checks across malware telemetry and agentic risk

Overview

This skill is a plausible PersistIQ integration, but it gives an agent broad authenticated ability to change sales records and workflows without clear confirmation rules.

Install only if you trust Membrane and want an agent to operate on your PersistIQ account. Use the least-privileged connection available, prefer discovered Membrane actions over raw proxy calls, and require explicit review before creating, updating, deleting, or bulk-changing contacts, campaigns, sequences, users, or outreach workflows.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
78% confidence
Finding
The invocation description is broad enough that an agent may select this skill for loosely related requests involving data, records, or automation, increasing the chance of unintended external actions against PersistIQ. In a connected environment, overbroad routing can cause unnecessary access to customer data or execution of operations the user did not specifically intend.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal