Accelo

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Accelo integration, but it gives an agent broad authenticated access to sensitive business data without enough guardrails for high-impact actions.

Install only if you trust Membrane and intend to let an agent operate on your Accelo data. Use a least-privilege Accelo account, prefer read-only discovery and listed actions, avoid administrator credentials, and require explicit confirmation before any create, update, delete, import, export, billing/payment, purchase, user/permission, backup, restore, or raw proxy request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
78% confidence
Finding
The skill advertises broad create/delete/import/export/archive/restore-style capabilities and state-changing actions without clearly warning that these operations can alter or remove user business data. In an agentic context, missing safety guidance increases the chance of unintended destructive actions being taken on production CRM/project data.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The direct API proxy feature allows arbitrary authenticated requests to the Accelo API, which can expose sensitive business records and perform destructive operations. Without explicit cautions, confirmation requirements, or guardrails, an agent could send unsafe requests or exfiltrate large volumes of CRM and operational data through the proxy.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal