Regfox

Security checks across malware telemetry and agentic risk

Overview

This RegFox skill appears legitimate, but it gives an agent broad authenticated ability to read or change event and registration data without clear approval limits.

Install only if you trust Membrane and are comfortable granting an agent access to your RegFox account. Use a least-privileged RegFox connection if possible, and require the agent to show the exact action, endpoint, data, and expected effect before approving any write, delete, refund, payment, attendee, registration, or ticketing change.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly documents a generic proxy request mechanism that can send arbitrary authenticated requests to the RegFox API, but it does not require user confirmation or warn that this enables broad read/write operations beyond curated actions. In an agent setting, this increases the chance of overbroad or unintended API use, including destructive changes or mass data access, especially because authentication is handled automatically.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal