Infisical

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Infisical integration, but it routes sensitive secrets-management access through Membrane and documents broad raw API operations without enough user-control guardrails.

Install only if you trust Membrane with the Infisical projects and environments you connect. Use least-privilege access, avoid raw proxy calls unless you explicitly requested them, confirm before reading, exporting, changing, or deleting secrets, and know how to revoke the Membrane connection afterward.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This skill documents a generic authenticated proxy mechanism for direct API requests to a secrets-management platform without guardrails around sensitive operations. In the context of Infisical, unrestricted proxying can enable broad retrieval, modification, or deletion of secrets and metadata, increasing the risk of accidental exfiltration or destructive actions.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal