Oracle Fusion Recruiting Cloud

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Oracle recruiting integration, but it gives an agent broad authenticated access to sensitive HR data, including raw write and delete API requests without clear safeguards.

Install only if you trust Membrane and intend to connect Oracle Fusion Recruiting Cloud. Use a least-privileged Oracle account, prefer curated actions over raw proxy requests, and require explicit user confirmation before any create, update, delete, approval, notification, offer, or workflow-changing operation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly documents a generic proxy request capability supporting POST, PUT, PATCH, and DELETE against the connected Oracle Recruiting API without requiring guardrails, confirmation, or warnings about destructive changes. In an agent context, this increases the chance that a model could perform unintended writes or deletions to recruiting data, especially because the proxy can bypass safer prebuilt actions and operate directly on arbitrary endpoints.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal