Enerflo

Security checks across malware telemetry and agentic risk

Overview

This Enerflo skill is a real Membrane integration, but it gives agents broad access to live business data and write-capable API operations without clear approval boundaries.

Install only if you trust Membrane and intend to let an agent work with live Enerflo data. Use a least-privilege Enerflo account, pin or review the CLI before global install, prefer listed read-only actions when possible, and require explicit approval before creating, updating, deleting, changing payments/orders/roles/permissions, or using raw proxy requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill is described so broadly ('Manage Organizations' / interact with Enerflo data) that an agent may invoke it for loosely related requests without clear scope or safety boundaries. In a system that can both read and modify external SaaS data, overbroad routing increases the chance of unintended data access or state-changing actions without sufficient user confirmation.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill advertises action execution and raw proxy requests to the Enerflo API, but it does not clearly warn that it can modify records or make arbitrary authenticated requests. This can mislead downstream agents or users into treating the skill as informational when it is actually capable of broad data mutation and direct API access.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal