Salesforce

Security checks across malware telemetry and agentic risk

Overview

This Salesforce skill is legitimate in purpose, but it deserves review because it can modify or delete CRM data through a persistent authenticated connection without explicit safety instructions.

Install only if you trust Membrane and need agent-driven Salesforce access. Prefer a least-privileged Salesforce account or sandbox, review the Membrane connection, and require explicit user confirmation before create, update, upsert, delete, bulk, composite, or proxy requests against production data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly documents destructive operations like delete-record and delete-multiple-records without any guidance to confirm user intent, verify target records, or warn about irreversible changes. In a CRM context, this can lead to accidental or overbroad deletion of production customer, sales, or support data if an agent executes these actions based on ambiguous prompts.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The proxy request feature allows arbitrary direct interaction with the Salesforce API using the authenticated connection, but the skill provides no warning that data will be transmitted to an external service or that custom endpoints can bypass safer pre-built actions. This increases the chance of unintended data exfiltration, unsafe writes, or use of sensitive endpoints without user awareness.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal