Sap Concur

Security checks across malware telemetry and agentic risk

Overview

This SAP Concur skill is coherent, but it gives agents broad authenticated power over sensitive travel and expense data without clear confirmation guardrails.

Install only if you trust Membrane and your organization permits SAP Concur access through it. Use a least-privileged Concur account, consider pinning the CLI version, and require explicit approval before creating, updating, deleting, submitting, approving, purchasing, or changing any SAP Concur record.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly documents a generic proxy-request capability that can send arbitrary HTTP methods to SAP Concur endpoints, but it does not warn that these calls may create, modify, or delete production travel/expense data. In an agent setting, this increases the chance of unintended state-changing operations because users may not realize that direct API calls are more dangerous than curated actions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal