Captain Data

Security checks across malware telemetry and agentic risk

Overview

This Captain Data skill is a coherent SaaS integration, but it gives an agent broad authority to run actions and raw API requests against a business account without clear guardrails.

Review this before installing if your Captain Data account has access to production data, billing, users, workspaces, or workflows. Use a least-privileged account or connection where possible, prefer prebuilt read-only actions, and require explicit confirmation before any create, update, delete, workflow execution, billing, team, workspace, or direct proxy API request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs the agent to run external actions and raw proxy API requests without requiring user confirmation or warning that these operations may transmit data externally or modify remote state. In an agent setting, this can lead to unintended data disclosure, workflow execution, or state-changing API calls against a live Captain Data account.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal