Tapfiliate

Security checks across malware telemetry and agentic risk

Overview

This is a real Tapfiliate integration, but it gives an agent broad authenticated power to change live affiliate, invoice, payout, and related business data without clear confirmation safeguards.

Install only if you are comfortable giving Membrane-mediated access to your Tapfiliate account. Prefer read-only discovery and prebuilt Membrane actions, explicitly approve any create/update/delete action or invoice/payout-related change, and revoke the Tapfiliate connection when it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill documents a generic proxy request mechanism supporting POST, PUT, PATCH, and DELETE against the Tapfiliate API without any warning or safety guidance around state-changing operations. In an agent setting, this increases the chance the agent will perform destructive or irreversible remote actions without explicit user confirmation or awareness.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal