Streak

Security checks across malware telemetry and agentic risk

Overview

This looks like a legitimate Streak CRM integration, but it gives agents broad authenticated CRM access, including direct API requests, without clear approval boundaries for risky changes.

Install only if you are comfortable connecting Streak through Membrane and allowing an agent to act on CRM data. Use a least-privileged Streak account, approve every create/update/delete and user/role change explicitly, prefer listed Membrane actions over raw proxy requests, and revoke the connection when no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation guidance is broad enough that an agent could activate this skill for loosely related requests involving Gmail, CRM, contacts, or sales workflows without a clear user request to use Streak specifically. That can lead to unnecessary external actions, unexpected data access, or operations against the wrong integration, especially in autonomous agent settings.

Vague Triggers

Low
Confidence
77% confidence
Finding
The instruction to use action names and parameters 'as needed' is underspecified and does not constrain how an agent should choose between read-only versus mutating actions. In practice this ambiguity can cause overbroad tool use, parameter misuse, or selection of higher-risk actions without explicit user confirmation.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal