Pushpay

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate Pushpay integration, but it gives broad authenticated access to sensitive donor and payment records without enough guardrails for changes or deletions.

Review before installing. Use a least-privileged Pushpay account, require confirmation before any create, update, delete, refund, payment, or bulk export action, prefer curated Membrane actions over raw proxy calls, and revoke the Membrane connection when no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill explicitly documents direct proxy requests with support for POST, PUT, PATCH, and DELETE against a donor-management platform without requiring confirmation, read-only preference, or warnings about sensitive financial/member data. In context, this increases the chance an agent will perform destructive or privacy-impacting operations or transmit sensitive records through raw requests without adequate user awareness.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal