Sellsy

Security checks across malware telemetry and agentic risk

Overview

This Sellsy skill is coherent, but it gives an agent broad authenticated CRM access, including direct API requests that can change or delete business records without explicit safety steps.

Install only if you trust Membrane with Sellsy access and are comfortable granting CRM permissions. Use least-privilege Sellsy access where possible, prefer predefined actions over raw proxy calls, and require explicit confirmation before creating, updating, deleting, exporting, or bulk-changing CRM data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly instructs the agent to run actions and send direct proxy requests to the external Sellsy API, including potentially state-changing HTTP methods, without requiring confirmation, scoping, or warning about data transmission and modification. In an agent setting, this can lead to unintended writes, deletions, or disclosure of CRM data to an external service based on ambiguous prompts.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal