Sifter

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real Membrane-based Sifter integration, but it gives broad authenticated account access and is not scoped tightly enough for automatic use.

Install only if you intend to connect Sifter through Membrane and trust the Membrane CLI. Verify the connection is for Sifter issue tracking, prefer discovered Membrane actions, and require explicit approval before any create, update, patch, delete, or raw proxy request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is presented as a Sifter-specific integration, but the documented connection flow can create or discover connectors for arbitrary apps based on any URL/domain. That expands the effective capability of the skill beyond its declared scope, enabling access to unintended external systems if an agent follows the instructions literally.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The proxy request section exposes arbitrary authenticated HTTP requests with multiple verbs, which effectively grants broad raw API access rather than limiting operations to vetted Sifter actions. In a skill advertised as Sifter data management, this bypasses scoping and safety expectations and could be used for destructive or unreviewed operations.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal