Netsuite

Security checks across malware telemetry and agentic risk

Overview

The skill appears to provide a broad NetSuite proxy that can reach sensitive ERP data without enough safety scoping for write or delete operations.

Review before installing. Use only with a NetSuite account you are authorized to connect, prefer predefined/read-only actions first, and require explicit approval showing the endpoint, method, record IDs, and payload before any POST, PUT, PATCH, DELETE, bulk, or unfamiliar proxy request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill documents a generic proxy mechanism that supports arbitrary HTTP methods, headers, and bodies against NetSuite, but it does not warn that these requests can create, update, or delete live ERP/accounting data. In a high-impact business system like NetSuite, omission of an explicit caution increases the chance an agent or user will perform destructive or non-reversible actions without adequate confirmation.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal