Recurly

Security checks across malware telemetry and agentic risk

Overview

This Recurly skill appears legitimate, but it gives an agent broad authenticated billing access without enough guardrails for write or delete actions.

Install only if you trust Membrane with the relevant Recurly account. Prefer least-privilege or test credentials where possible, use curated Membrane actions before raw proxy calls, and require explicit confirmation before creating, updating, or deleting billing, subscription, invoice, transaction, or account data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly documents a generic proxy mechanism that supports state-changing HTTP methods like POST, PUT, PATCH, and DELETE against the Recurly API, but it does not warn that these operations can create, modify, or delete billing and subscription data. In a billing context, omission of mutation-safety guidance increases the chance an agent will perform destructive or financially impactful actions without confirmation or scoping safeguards.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal