Teamcity

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate TeamCity integration, but it gives agents broad authenticated API access that can change CI/CD resources without clear confirmation safeguards.

Install only if you trust the publisher and are comfortable letting an agent use authenticated TeamCity access through Membrane. Require explicit confirmation for any non-GET proxy request, and avoid administrative or destructive TeamCity endpoints unless the exact action and target have been approved.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly documents a generic proxy request mechanism supporting destructive HTTP methods like POST, PUT, PATCH, and DELETE without requiring confirmation or warning that these operations may alter or delete remote TeamCity resources. In an agent context, this increases the chance of unintended state-changing actions against CI/CD infrastructure, especially if the model infers that direct API access is acceptable when prebuilt actions are unavailable.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal