ziniao-sso-doc

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only SSO integration skill that discusses sensitive business APIs but does not install code or perform actions itself.

Install only if you need Ziniao SSO integration reference material. Treat any API keys, app tokens, user login tokens, employee lists, account mappings, and superbrowser:// links as sensitive: use authorized business access only, minimize queries, avoid pasting secrets into chats or logs, and confirm with the user before calling APIs or opening, closing, or exiting browser sessions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
This documentation describes endpoints that expose employee and account metadata, including names, phone numbers, usernames, login-related identifiers, and account access mappings, but it provides no privacy, authorization, or least-privilege guidance. In a skill meant to help ERP SSO integration, this can normalize broad querying of sensitive data and make misuse easier by integrators who may not implement adequate access controls or auditing.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal