Taskade

Security checks across malware telemetry and agentic risk

Overview

This Taskade integration appears legitimate, but it gives an agent broad authenticated ability to change or delete Taskade workspace data without clear confirmation safeguards.

Install only if you are comfortable granting Membrane-mediated access to your Taskade account. Prefer pre-built Membrane actions, use a limited or test workspace when possible, and require explicit approval before the agent creates, edits, or deletes Taskade data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly instructs the agent to use generic proxy requests, including POST, PUT, PATCH, and DELETE, without requiring confirmation or emphasizing that these methods can modify or delete user data. In an agent setting, this increases the risk of unintended destructive actions if a model interprets a vague user request too aggressively or uses the proxy as a fallback without adequate safeguards.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal