Teamgate

Security checks across malware telemetry and agentic risk

Overview

This CRM integration is not malicious, but it should be reviewed because it gives an agent broad authenticated power to change or delete business records through raw API calls without explicit safety steps.

Install only if you trust Membrane and intend to let the agent operate on the connected CRM account. Use the least-privileged account or workspace possible, prefer predefined Membrane actions, and require explicit approval before any POST, PUT, PATCH, DELETE, bulk change, or raw proxy request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The documentation explicitly enables direct proxy requests with GET, POST, PUT, PATCH, and DELETE methods but does not require confirmation before mutating operations. In a CRM context, this can lead an agent to create, alter, or delete customer records through raw API calls without sufficient guardrails, increasing the chance of unintended data modification.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal