Railz

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Railz integration, but it gives an agent broad access to sensitive financial data and possible write/delete API requests without clear approval safeguards.

Install only if you intend to let an agent work with Railz financial data through Membrane. Use a least-privileged Railz/Membrane account, prefer discovered read-only actions, and require the agent to show the exact endpoint, method, payload, and expected effect before any create, update, delete, or raw proxy request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The skill explicitly documents raw proxy requests supporting POST, PUT, PATCH, and DELETE, but does not require confirmation or warn about external state changes. In an agent setting, this can lead to unintended modification or deletion of financial/accounting data if the model chooses direct API calls without an explicit user checkpoint.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal