Zoho Assist

Security checks across malware telemetry and agentic risk

Overview

This Zoho Assist skill appears legitimate, but it gives broad authenticated API access that could change or delete live remote-support data without clear built-in guardrails.

Review before installing if your Zoho Assist account can access customer sessions, unattended computers, contacts, or schedules. Use a least-privilege Zoho account, confirm every write or delete operation before allowing it, review Membrane’s data handling, and consider pinning the Membrane CLI version instead of installing @latest.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly documents a generic proxy mechanism that supports state-changing methods like POST, PUT, PATCH, and DELETE without any accompanying warning, confirmation requirement, or guidance to verify user intent before destructive operations. In a remote-support product context, this could enable unintended modification of sessions, devices, contacts, or schedules if an agent uses the proxy directly from ambiguous user prompts.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal