Solar Nexus

Security checks across malware telemetry and agentic risk

Overview

This looks like a legitimate Solar Nexus integration, but it gives an agent authenticated write-capable access to business records without clear confirmation guardrails.

Install only if you trust Membrane and intend to let an agent work with the connected Solar Nexus account. Before using it, require the agent to summarize the exact record and field changes and get your approval before any create, update, complete, delete, or raw proxy request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill advertises multiple state-changing operations such as creating projects, updating milestones, and adding log entries, but it does not instruct the agent to obtain explicit user confirmation before executing them. In an agent setting, this creates a real risk of unintended writes to production Solar Nexus data through over-eager automation or ambiguous user requests.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal