U301

Security checks across malware telemetry and agentic risk

Overview

The skill is instruction-only, but its U301 identity is inconsistent while it asks agents to use authenticated tooling that can change or delete data.

Install only after confirming the correct U301 service, publisher, API documentation, and Membrane connection target. Use the least-privileged account available, prefer discovered read-only actions, and require explicit confirmation before creating, updating, disabling, or deleting links, records, domains, or account data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill documents a generic authenticated proxy mechanism that supports arbitrary HTTP methods, including POST, PUT, PATCH, and DELETE, without requiring confirmation or emphasizing destructive risk. In a data-management integration, this can enable unintended record changes or deletions if an agent uses the proxy directly based on ambiguous user intent or hallucinated endpoints.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal