Broadridge

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Broadridge integration, but it gives an agent broad authenticated access to sensitive financial-business data without clear safeguards for changes or deletes.

Install only if you are comfortable granting Membrane-mediated access to Broadridge. Use the least-privileged account available, verify or pin the Membrane CLI, and require explicit approval before any create, update, delete, or raw proxy request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly documents proxying arbitrary API requests and supports mutating HTTP methods like POST, PUT, PATCH, and DELETE without warning about side effects or requiring user confirmation. In a financial-services integration handling records, documents, tasks, and workflows, this can lead to unintended modification or deletion of remote data if the agent chooses raw requests over safer scoped actions.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal