Yodiz

Security checks across malware telemetry and agentic risk

Overview

This Yodiz integration is coherent, but it gives an agent broad authenticated ability to change or delete project records without clear confirmation safeguards.

Install only if you are comfortable letting Membrane broker access to your Yodiz workspace. Use a least-privileged Yodiz account where possible, prefer discovered Membrane actions over raw proxy calls, and review any create, update, or delete operation before allowing it to run.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill documents a generic proxy request capability that supports mutating HTTP methods like POST, PUT, PATCH, and DELETE, but it does not explicitly warn that these operations can modify or delete Yodiz data. In an agent setting, omission of a confirmation or caution pattern increases the risk of unintended destructive actions against live project records.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal