Oracle Marketing Cloud

Security checks across malware telemetry and agentic risk

Overview

This Oracle Marketing Cloud skill is mostly coherent, but it exposes broad authenticated API access that could change or delete marketing data without explicit guardrails.

Install only if you trust Membrane and intend to let the agent operate on Oracle Marketing Cloud data. Before using raw proxy requests or send/update/delete actions, require the agent to summarize the exact endpoint, method, target records, and expected impact, then confirm before execution.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill explicitly documents a generic authenticated proxy request mechanism that can perform arbitrary GET, POST, PUT, PATCH, or DELETE operations against Oracle Marketing Cloud without requiring a confirmation step or warning for data-modifying actions. In an agent setting, this increases the chance of unintended destructive or privacy-impacting operations because broad API capability is exposed through natural-language tasking.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal