Back to skill

Security audit

雄韬CRM - opencrm

Security checks across malware telemetry and agentic risk

Overview

This skill is a clearly scoped CRM connector that reads and adds XTOCN CRM records using a disclosed API and required CRM token.

Install only if you intend agents to use your XTOCN CRM account. Treat pasted company dossiers and contact details as data sent to the disclosed CRM API, and review parsed fields before confirming customer creation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill sends customer and lead information to an external CRM API but does not clearly warn users that their provided business data will be transmitted off-platform. This can cause unintended disclosure of sensitive commercial or personal information, especially when users paste raw company dossiers or contact details.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.