Uservoice

Security checks across malware telemetry and agentic risk

Overview

This UserVoice skill appears legitimate, but it gives an agent broad authenticated ability to change or delete UserVoice data without clear approval guardrails.

Install only if you trust Membrane and are comfortable granting it access to your UserVoice account. Use the least-privileged UserVoice account available, prefer listed Membrane actions over raw proxy calls, and require explicit human approval before creating, updating, posting, or deleting UserVoice data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill explicitly documents a generic proxy request mechanism supporting POST, PUT, PATCH, and DELETE against the UserVoice API, but it does not instruct the agent to confirm destructive operations or distinguish safe read actions from mutating ones. In an agent context, this increases the chance of unintended data modification, deletion, or workflow-triggering actions being executed on behalf of the user.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal