Signrequest
Security checks across malware telemetry and agentic risk
Overview
This SignRequest skill is a coherent Membrane-based integration, but it gives an agent broad authenticated ability to act on legally and business-sensitive e-signature, team, and user data without clear mutation safeguards.
Install only if you trust Membrane and are comfortable granting delegated access to the intended SignRequest account. Before letting an agent run actions or proxy requests, confirm the exact account, endpoint, method, and data changes, especially for document workflows, signatures, teams, users, and any DELETE/PATCH/POST/PUT operation.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
63/63 vendors flagged this skill as clean.
