Zendesk Guide

Security checks across malware telemetry and agentic risk

Overview

This appears to be a normal Zendesk Guide integration, but users should be careful because it can use authenticated API calls that change or delete Guide content.

Install only if you intend to let an agent operate on Zendesk Guide through your authenticated Membrane connection. Prefer discovered Membrane actions first, and require explicit approval before any request that creates, updates, publishes, archives, or deletes Guide content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly documents raw proxy requests with support for destructive HTTP methods such as DELETE, POST, PUT, and PATCH, but does not warn that these operations can modify or permanently remove Zendesk Guide content. In an agent setting, this increases the chance of unsafe autonomous actions or accidental data loss because the documentation normalizes direct state-changing API use without requiring confirmation or guardrails.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal