Talkdesk

Security checks across malware telemetry and agentic risk

Overview

This Talkdesk skill is broadly coherent, but it gives an agent raw authenticated API access that can change or delete business data without clear confirmation safeguards.

Review before installing if this will connect to a production Talkdesk account. Prefer Membrane prebuilt actions, avoid raw proxy calls unless necessary, and require explicit confirmation before any POST, PUT, PATCH, or DELETE request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly documents raw proxy requests with mutating methods like POST, PUT, PATCH, and DELETE, but does not require confirmation, read-only defaults, or warnings about destructive effects. In an agent setting, this increases the chance of unintended record modification or deletion in a live Talkdesk environment, especially when the model falls back to direct API calls instead of safer prebuilt actions.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal