Chartmogul

Security checks across malware telemetry and agentic risk

Overview

This is a coherent ChartMogul integration, but it gives an agent broad ability to change or delete live business records without clear confirmation safeguards.

Install only if you want an agent to operate on your ChartMogul account through Membrane. Use the least-privileged ChartMogul/Membrane access available, start with read-only queries, and require explicit confirmation with the exact record ID before any create, update, delete, bulk, or raw proxy request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill documents a delete capability without any guidance to require user confirmation, dry-run validation, or safeguards before destructive operations. In an agentic context, this increases the chance of accidental or overly broad deletion of customer data if an agent interprets a prompt too aggressively.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal