Rasa

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Rasa integration, but it gives an agent broad authenticated access that can include raw write or delete requests without built-in confirmation guidance.

Install only if you trust Membrane and need an agent to manage Rasa. Use a least-privileged Rasa or test account where possible, and require explicit user confirmation before any create, update, delete, permission, model, tracker, or user-management request, especially when using the raw proxy.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly documents a generic proxy mechanism that supports POST, PUT, PATCH, and DELETE against the remote Rasa API, but it does not require user confirmation or warn that these operations may modify or delete production assistant data. In an agent setting, this increases the chance of unintended destructive actions because the model is encouraged to use direct API access when prebuilt actions are insufficient.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal