Sendcloud

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Sendcloud shipping integration, but users should be careful because it can change live parcel data.

Install only if you intend to let an agent access your Sendcloud account through Membrane. Before create, update, cancel/delete, label purchase, or raw proxy requests, require the agent to show the action or endpoint, affected parcel IDs, payload, and expected account impact, then approve it explicitly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly documents state-changing operations such as creating, updating, cancelling, and deleting parcels, plus raw proxy requests, but does not instruct the agent to obtain explicit user confirmation before performing destructive or externally visible actions. In an agent setting, this omission can lead to unintended shipment creation, cancellation, or other account changes if the model acts on ambiguous prompts or over-automates workflows.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal