Fraudlabs Pro

Security checks across malware telemetry and agentic risk

Overview

This FraudLabs Pro skill is transparent about its integration purpose, but it gives broad authenticated power to change fraud controls and business records without clear confirmation boundaries.

Install only if you are comfortable giving an agent access to your FraudLabs Pro account through Membrane. Use a least-privilege connection, verify or pin the Membrane CLI where possible, and require the agent to show exact parameters and get approval before creating, updating, deleting, blacklisting, whitelisting, sending SMS, or using raw proxy requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill advertises destructive capabilities such as creating and deleting blacklist/whitelist entries and updating transaction records without clearly warning that these actions can alter fraud controls and business records. In an agent context, that increases the chance of unintended high-impact changes if a user request is ambiguous or the agent acts without explicit confirmation.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal