Spaycial

Security checks across malware telemetry and agentic risk

Overview

This instruction-only Spaycial skill is not malicious, but it grants broad Membrane-powered API and account automation authority without enough scoping or confirmation guidance.

Review before installing. Use a low-privilege Membrane/Spaycial account when possible, avoid connecting billing or admin scopes unless needed, and require explicit confirmation before any create, update, delete, approval, payment, purchase, transfer, purge, restore, or raw API request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly documents raw action execution and proxy API requests, including POST, PUT, PATCH, and DELETE, without requiring confirmation before state-changing operations. In a high-privilege SaaS integration, that omission can lead an agent to perform destructive or irreversible changes based on ambiguous prompts, increasing the risk of unauthorized modification, deletion, or workflow execution.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal