Back to skill

Security audit

pipedrive-api

Security checks across malware telemetry and agentic risk

Overview

This appears to be a Pipedrive API helper, but it requests broad shell and file authority and contains generic, contradictory documentation that should be reviewed before use.

Install only if you intend to use Maton/Pipedrive API access and are comfortable with CRM data being sent through the documented remote endpoint under your API key. Grant the skill only task-specific access, avoid using it for generic automation, and do not allow broad shell or filesystem actions unless you explicitly requested and reviewed them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is presented as a Pipedrive API integration, but its documented capabilities expand into generic file processing and command execution. This creates a scope mismatch that can cause an agent or user to grant broader trust and permissions than necessary, increasing the chance of misuse under the cover of a narrowly branded integration.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Declaring generic command-execution capability for a CRM/API integration is dangerous because it gives the skill power to run arbitrary system commands unrelated to its stated function. In an agent environment, this materially increases the blast radius from simple API usage to local system manipulation, data exfiltration, or execution of attacker-influenced commands.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The skill claims broad file read/write support even though its stated purpose is Pipedrive API access. Unnecessary filesystem access expands exposure to local sensitive data and enables unintended persistence or tampering that is unrelated to the advertised CRM workflow.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The '专业版专属特性' section advertises unrelated static analysis, vulnerability scanning, and CI/CD features that contradict the skill's claimed Pipedrive purpose. This kind of contradictory documentation can mislead routing and trust decisions, obscuring the real scope of the skill and normalizing broader access than users expect.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The invocation language is so broad that the skill may be selected for many generic efficiency, automation, or workflow requests that are not specifically about Pipedrive. Over-broad routing language can cause accidental activation in contexts where its permissions and external connectivity are unnecessary, increasing the chance of inappropriate data handling or tool use.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The examples show authenticated external requests using an API key, but they do not prominently warn that task data may be transmitted to a remote third-party service. In an agent setting, this can lead users to expose sensitive business or personal data without informed consent, especially when the skill appears to be a general workflow utility.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.