Zulip

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Zulip integration, but it can read and send chat content using the permissions of the configured bot account.

Install only if you intend to let an agent use a Zulip bot account. Use a restricted bot, protect the `zuliprc` API key, avoid putting real keys directly in shell commands, and review recipients, topics, message content, and uploaded files before allowing send or upload actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly supports reading private messages, sending messages, and uploading files to an external SaaS platform but does not include any warning, consent boundary, or guidance on handling sensitive data. This creates a real privacy and data-governance risk because an agent could access or transmit confidential content to Zulip without the user clearly understanding that external communication is occurring.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal