Ftrack

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate FTrack integration, but it gives an agent broad ability to change or delete project data without explicit confirmation safeguards.

Install only if you want an agent to operate on real FTrack data. Use a least-privilege FTrack/Membrane account, review action inputs before execution, and require explicit confirmation for deletes, broad updates, raw proxy requests, and changes affecting projects, tasks, users, or activities.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill advertises destructive actions such as deleting projects and tasks but provides no guidance to require user confirmation, authorization checks, or safety interlocks before use. In an agent setting, that omission can enable accidental or unauthorized destructive operations if the model infers it should execute a deletion from ambiguous user intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal