Veracode

Security checks across malware telemetry and agentic risk

Overview

This Veracode skill is mostly coherent, but it gives an agent broad authenticated API access, including write and delete requests, without clear approval limits.

Install only if you trust Membrane and are comfortable granting delegated Veracode access. Use a least-privilege Veracode account, require the agent to confirm before any non-read or raw proxy request, and review exact endpoints and payloads before update or delete operations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly documents direct proxy requests with arbitrary HTTP methods, including destructive verbs like DELETE, but does not require confirmation, constrain endpoint scope, or warn about state-changing effects. In an agent setting, this increases the chance that the model performs unsafe write or delete operations against a live Veracode tenant based on ambiguous or malicious prompts.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal