Appfire

Security checks across malware telemetry and agentic risk

Overview

This Appfire skill is a legitimate integration, but it gives an agent broad authenticated API access that could change or delete business data without clear confirmation rules.

Install only if you intend to let an agent operate Appfire through Membrane. Use the least-privileged Appfire/Membrane connection available, review requested permissions, and require explicit approval before any write, update, delete, bulk, or raw proxy API request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly documents arbitrary proxied API requests, including POST, PUT, PATCH, and DELETE, without guardrails around sensitive data transmission or destructive operations. In an agent setting, this can normalize direct state-changing requests and increase the chance of unintended modification, deletion, or overbroad data access if the agent follows user prompts without additional confirmation.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal