Scraptio

Security checks across malware telemetry and agentic risk

Overview

This Scraptio skill is a disclosed Membrane-based integration that can access and change Scraptio data, but the sensitive capabilities match its stated purpose.

Install only if you trust Membrane and the npm CLI package, connect the specific Scraptio account you intend to use, and review any POST, PUT, PATCH, or DELETE request before allowing the agent to run it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill explicitly encourages direct proxy requests to the external API without requiring confirmation, allowlisting, or warning about the risks of raw endpoint access. In an agent setting, this can bypass safer pre-built actions and increase the chance of unintended state-changing requests, overbroad data access, or misuse of authenticated capabilities against the connected Scraptio account.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal