Zoho Sign

Security checks across malware telemetry and agentic risk

Overview

This Zoho Sign skill appears legitimate, but it gives an agent broad access to sensitive signing workflows without clear safeguards before high-impact actions.

Install only if you are comfortable granting Membrane-mediated access to the intended Zoho Sign account. Require the agent to show the exact document, recipient, action or endpoint, method, and payload before any send, sign, create, update, or delete operation, and revoke the Membrane or Zoho connection when it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The description is broad enough to invoke the skill for generic 'data, records, and automate workflows' requests, which can cause an agent to select this skill outside a clearly scoped Zoho Sign e-signature task. In a system that auto-selects skills, that overbreadth can lead to unintended access to sensitive document workflows or execution of actions the user did not specifically intend.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill gives direct instructions for running actions and proxying arbitrary API requests, including methods that can modify or send documents, but it does not require user confirmation or warn about side effects. In the context of Zoho Sign, those operations can expose confidential documents, trigger signature workflows, or alter signing state, making silent execution risky.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal