Solve Crm

Security checks across malware telemetry and agentic risk

Overview

This Solve CRM skill is legitimate in purpose, but it can change or delete live CRM records without documented confirmation safeguards.

Install only if you trust Membrane and intend to let an agent access your Solve CRM account. Use least-privilege CRM access where possible, verify the tenant and target records, and require explicit human confirmation before any create, update, delete, bulk action, or raw proxy request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
72% confidence
Finding
The invocation description is broad enough that the skill may be selected for loosely related CRM requests, increasing the chance of unintended access to customer data or execution of write operations in the wrong context. In a CRM integration with create, update, and delete capabilities, overbroad routing raises the risk of accidental data exposure or modification.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill advertises delete actions for contacts, companies, and tickets without any warning, confirmation, or safety guidance. In a live CRM environment, this increases the risk of accidental or premature destructive operations that could permanently remove business records and disrupt operations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal