Faktoora

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent Faktoora accounting integration, but it gives agents broad authority to change or delete financial business records without clear confirmation or rollback guidance.

Install only if you trust Membrane and intend to let an agent work with your Faktoora accounting data. Before any create, update, delete, webhook, or raw proxy request, require the agent to show the exact target account, resource IDs, and intended change, then confirm explicitly. Revoke the Membrane/Faktoora connection when it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
72% confidence
Finding
The invocation description is broad enough that an agent may select this skill for many generic requests involving Faktoora, even when the requested operation is ambiguous or outside the user's intended scope. In an integration that can list, create, update, and delete business records, overbroad routing increases the chance of unintended actions on sensitive accounting data.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill advertises delete operations for invoices, products, and customers without any guidance to require explicit confirmation, display object identifiers, or warn about irreversibility. In an accounting context, accidental or prompt-induced deletion can cause loss of financial records, operational disruption, and compliance issues.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal