Screensteps
Security checks across malware telemetry and agentic risk
Overview
This appears to be a legitimate ScreenSteps integration, but it needs Review because it gives an agent broad authenticated access that can change or delete knowledge-base content.
Install only if you are comfortable giving Membrane-mediated access to ScreenSteps. Use a least-privilege ScreenSteps account, verify the Membrane CLI package before global installation, require explicit confirmation before POST, PUT, PATCH, or DELETE actions, and revoke the Membrane connection when it is no longer needed.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
63/63 vendors flagged this skill as clean.
