Pusher

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Zoho Cliq integration through Membrane, with normal integration risks around account permissions and write-capable API access.

Install only if you trust Membrane and intend to connect Zoho Cliq. Use the least-privileged Zoho/Membrane account available, review requested permissions, prefer listed Membrane actions over raw proxy calls, and explicitly approve any action that creates, changes, posts, or deletes Zoho data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The proxy request section documents arbitrary direct API calls, including POST, PUT, PATCH, and DELETE, without warning that these operations may modify or delete remote data. In an agent context, this increases the risk that the model will perform destructive actions through a generic request mechanism without explicit user confirmation or adequate safeguards.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal