Zoho Sheet

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Zoho Sheet integration that uses Membrane for authenticated spreadsheet access, with a powerful raw API option users should handle carefully.

Install only if you trust Membrane with the Zoho Sheet account you connect. Prefer listed Membrane actions over raw proxy requests, use the least-privileged Zoho account practical, and explicitly approve any update, bulk edit, or delete before it runs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill explicitly enables direct proxied network requests to the Zoho Sheet API and discusses write-capable HTTP methods, but it does not instruct the agent to warn or confirm with the user before modifying remote spreadsheet data. In practice, this can lead to unintended destructive actions, silent data changes, or overly broad API use without clear user awareness.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal