Osticket

Security checks across malware telemetry and agentic risk

Overview

This is a coherent osTicket integration, but it gives an agent broad raw API access that could change or delete ticket data without clear confirmation guardrails.

Install only if you intend to let the agent operate on an osTicket instance through Membrane. Prefer prebuilt Membrane actions and read-only or least-privilege osTicket credentials where possible, and require explicit confirmation for any POST, PUT, PATCH, or DELETE request, including the exact endpoint and target records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly documents a raw proxy request capability with support for POST, PUT, PATCH, and DELETE, but does not require confirmation or warn that these operations can modify or delete ticketing data. In an agent setting, this increases the risk that a model could perform destructive actions against OsTicket records based on ambiguous prompts or planning errors.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal