Signwell

Security checks across malware telemetry and agentic risk

Overview

This SignWell skill is coherent but gives an agent broad authenticated power to change or delete sensitive signing documents and account data through a raw API proxy.

Install only if you are comfortable giving Membrane-mediated access to your SignWell account. Use the least-privileged SignWell account available, prefer curated Membrane actions, explicitly confirm any create/update/send/delete operation, and revoke the Membrane connection when it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill exposes a generic authenticated proxy request mechanism that can issue arbitrary HTTP methods against the SignWell API, including potentially destructive endpoints, without embedding guardrails or confirmation requirements. In an agent setting, this expands capability beyond curated actions and increases the risk of unintended modification, deletion, or bulk operations if the agent misinterprets a prompt or is manipulated.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal